Hackers posing as Ukraine’s Security Service infect 100 govt PCs
ID: 6efab98e-db7a-50c3-b433-725c36154613
STIX ID: report--6efab98e-db7a-50c3-b433-725c36154613
Feed Name: Bleeping Computer
Threat Score
Attackers impersonating Ukraine's Security Service (SSU) used spear-phishing emails with a Documents.zip lure that downloaded a malicious MSI to deploy AnonVNC, compromising over 100 central and local government systems since mid-July 2024; CERT-UA attributes the campaign to UAC-0198 and observed some samples signed with a Shenzhen Variable Engine E-commerce Co Ltd code-signing certificate.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
