logo

Russia-Ukraine Conflict: Key Cyber Incidents

ID: 8c00f968-1bdd-51ff-8a1b-ecd9c4e32e11

STIX ID: report--8c00f968-1bdd-51ff-8a1b-ecd9c4e32e11

Feed Name: Cyble Blog

Threat Score
75/100

Date Published: 2025-11-27

Date Updated: 2026-07-16

...
...

This report summarizes active cyber threats exploiting the Russia–Ukraine conflict: a destructive .NET wiper named RURansom (irreversible file corruption and ransom notes), a MicroBackdoor deployment attributed to Belarus-linked UAC-0051 (via malicious .chm and chained VBScript/.NET loader), and multiple malspam campaigns delivering AgentTesla, FormBook, and QuasarRAT; the publication includes extensive IoCs and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.