Ukraine says hackers abuse SyncThing data sync tool to steal data
ID: d97ca538-c605-5469-9a73-7a5dd731959d
STIX ID: report--d97ca538-c605-5469-9a73-7a5dd731959d
Feed Name: Bleeping Computer
Threat Score
**SickSync (UAC-0020 / Vermin)** — CERT-UA reports an active espionage campaign using a modified SyncThing client paired with modular SPECTR malware to steal files, credentials, and screenshots from Ukrainian defense targets; the infection vector is a phishing email delivering a password‑protected RAR that drops SyncThing, SPECTR, and a launcher, and stolen data is exfiltrated via SyncThing peer-to-peer synchronization.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
