Hybrid Russian Espionage and Influence Campaign Aims to Compromise Ukrainian Military Recruits and Deliver Anti-Mobilization Narratives
ID: 917e824e-42bc-53a2-a607-eaf7eb8bcaa8
STIX ID: report--917e824e-42bc-53a2-a607-eaf7eb8bcaa8
Feed Name: Google Cloud Threat Intelligence
Threat Score
The Civil Defense website distributed multi-stage malware for Windows and Android: a custom Pronsis Loader (CivilDefense.exe) that chains to a PHP/JVM-compiled downloader and ultimately deploys the PURESTEALER .NET infostealer (MD5s provided), and an Android APK variant that delivers the CRAXSRAT backdoor; the report includes MD5 hashes and a download URL as IOCs and describes the delivery and capabilities of both payloads.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
