Russian Hackers Target Ukraine with Disinformation and Credential-Harvesting Attacks
ID: f6cb5f71-5e8a-5353-869e-88d18bbc546c
STIX ID: report--f6cb5f71-5e8a-5353-869e-88d18bbc546c
Feed Name: The Hacker News
Threat Score
Researchers identified ‘Operation Texonto,’ a Russia-aligned influence operation that ran disinformation email waves in Nov–Dec 2023 and spear-phishing targeting Ukrainian entities and EU organizations to harvest credentials via fake sign-in pages; the report also highlights related pro‑Kremlin campaigns (Doppelganger NG) with overlaps to known APTs (COLD RIVER, APT28) and notes infrastructure misuse such as the infonotification.com domain and compromised Ubiquiti devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
