Ukrainian Government Systems Targeted With Backdoors Hidden in Cloud APIs and Docs

Ukrainian Government Systems Targeted With Backdoors Hidden in Cloud APIs and Docs

Russian-linked hackers, specifically APT28 or Fancy Bear, have launched a sophisticated cyberattack targeting Ukrainian government systems with new malware strains and covert communication methods. This campaign highlights the evolving tactics of state-sponsored cyber espionage, using legitimate cloud services as command-and-control channels. #APT28 #FancyBear #UkrainianGovernmentSystems

Keypoints

  • Russia-linked APT28 targeted Ukrainian government systems with new stealthy malware strains.
  • The attackers used macro-laced Word documents delivered via Signal for initial compromise.
  • Malware BEARDSHELL and SLIMAGENT are designed for covert data collection and screen capture.
  • The campaign utilized legitimate cloud services like Icedrive and Koofr as command-and-control infrastructure.
  • Security teams are advised to monitor traffic to specific cloud API endpoints and user macro activity.

Read More: https://thecyberexpress.com/ukrainian-government-systems-targeted/