logo

Russian Hackers Target Ukraine with Disinformation and Credential-Harvesting Attacks

ID: f6cb5f71-5e8a-5353-869e-88d18bbc546c

STIX ID: report--f6cb5f71-5e8a-5353-869e-88d18bbc546c

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-02-21

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers identified ‘Operation Texonto,’ a Russia-aligned influence operation that ran disinformation email waves in Nov–Dec 2023 and spear-phishing targeting Ukrainian entities and EU organizations to harvest credentials via fake sign-in pages; the report also highlights related pro‑Kremlin campaigns (Doppelganger NG) with overlaps to known APTs (COLD RIVER, APT28) and notes infrastructure misuse such as the infonotification.com domain and compromised Ubiquiti devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.