Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » A Russian spy group sent malware to the Ukrainian military via Telegram
Global Security

A Russian spy group sent malware to the Ukrainian military via Telegram

AdminBy AdminOctober 28, 2024No Comments3 Mins Read
Malware via Telegram
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


October 28, 2024Ravi LakshmananCyber ​​espionage / Android

Malware via Telegram

An alleged Russian hybrid espionage-influence operation was spotted delivering a mixture of Windows and Android malware to target the Ukrainian military called Telegram Civil Defense.

Google Threat Analysis Group (TAG) and Mandiant track activity under the name UNC5812. A threat group that runs a Telegram channel called civildefense_com_uawas created on September 10, 2024. At the time of writing, the channel has 184 subscribers. It also supports the website civildefense.com(.)ua, which was registered on April 24, 2024.

“Civil Defense claims to be a provider of free software designed to allow potential recruits to view and share crowdsourced locations of Ukrainian military recruiters,” the company said in a statement. said in a report shared with The Hacker News.

When installed on Android devices with Google Play Protect disabled, these apps are designed to deploy operating system-specific commercial malware along with a rogue mapping app called SUNSPINNER.

Cyber ​​security

UNC5812 is also said to be actively involved in influence operations, spreading stories and soliciting content aimed at undermining support for Ukraine’s military mobilization and recruitment efforts.

“Campaign UNC5812 is highly representative of Russia’s emphasis on achieving cognitive impact through its cyber capabilities, and highlights the important role that messaging apps continue to play in the delivery of malware and other cyber dimensions of Russia’s war in Ukraine,” the Google Threat Intelligence Group said. .

Civil Defense, whose Telegram channel and website promoted other legitimate, Ukrainian-language Telegram channels, aims to direct victims to its website, which downloads malware depending on the operating system.

For Windows users, the ZIP archive leads to the deployment of the newly discovered PHP-based Pronsis malware downloader used to distribute SUNSPINNER and the standard PureStealer malware, which is advertised for prices ranging from $150 for a monthly subscription to $699 for a lifetime license.

Malware via Telegram

SUNSPINNER, for its part, shows users a map depicting the alleged location of Ukrainian military recruits from a command and control (C2) server operated by the actor.

For those accessing the website from Android devices, the attack chain deploys a malicious APK file (package name: “com.http.masters“), which embeds a remote access trojan called CraxsRAT.

The website also contains instructions that guide victims on how to disable Google Play Protect and grant it all the requested permissions, allowing the malware to run unhindered.

CraxsRAT is a a well-known family of Android malware which comes with remote device control capabilities and advanced spying features such as keyboard, gesture control, and camera, screen, and call recording.

Cyber ​​security

After the malware was publicly exposed Cyfirma in late August 2023 EVLF, the threat creator behind the project, decided to cease operations, but not before selling its Telegram channel to a Chinese-speaking threat creator.

As of May 2024, EVLF is said to be development stopped about malware due to scammers and hacked versions, but said they are working on a new web version that can be accessed from any machine.

“While the Civil Defense website also advertises support for macOS and iPhone, only Windows and Android payloads were available at the time of analysis,” Google said.

“The website’s FAQ contains a strained justification for hosting the Android app outside of the App Store, suggesting it is an attempt to ‘protect the anonymity and security’ of its users, and directing them to a set of accompanying video instructions.”

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025

Lack of the TP-Link Cve-2023-33538 router under active operation, CISA releases an immediate warning

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.