Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Russia associated with homoredon uses baits related to troops
Global Security

Russia associated with homoredon uses baits related to troops

AdminBy AdminMarch 31, 2025No Comments3 Mins Read
Deploy Remcos RAT in Ukraine
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 31, 2025Red LakshmananIntelligence threats / malicious software

Remove Ram Remcos in Ukraine

Subjects in Ukraine were aimed at a phishing campaign aimed at distributing Trojan remote Rat Remecos.

“File names use Russian words related to troops in Ukraine as a bait,” Cisco Talos Guilherme Venere researcher – Note In a report published last week. “Loading PowerShell is in contact with geo-aggregated servers located in Russia and Germany to download the mail file in the second stage containing Backdoor Remcos.”

Activities has been associated with moderate confidence for a Russian hacking group known as HomoredonAlso tracked under Monikers Aqua Blizzard, Armageddon, Blue Otso, Bluealpha, Hive0051, Iron Tilden, Primitive Bear, Shuckworm, Trident Ursa, UAC-20010, UAC530 and Winterflounder.

Cybersecurity

The actor of the threat, which is estimated with the Russian Federal Security Service (FSB), is known for his orientation to Ukrainian organizations for espionage and theft of data. It has been operating at least since 2013.

The latest company is characterized by the distribution of Windows Shortcut files (LNK), compressed inside the ZIP archives, masking them into Microsoft Office documents related to the current Russo-Sukrainian war to cheat the recipients. It is believed that these archives are sent through phishing.

Gamaredon links follow from the use of two machines used when making malicious label files and which were previously used by threatening the actor for such purposes.

The LNK files are shipped with the PowerShell code, which is responsible for downloading and executing the next useful CMDlet Get-Command load, as well as receiving the bait file that is displayed to keep the blow.

The second stage is another ZIP archive, which contains malicious DLL, which will be made using the technique called Dll Baysing. Dll is a loader that transcripts and launches the final useful load of Remcos from encrypted files present in the archive.

The disclosure of information occurs as a silent impetus in detail about a phishing campaign that uses bait sites to collect information against Russian persons who sympathize with Ukraine. It is assumed that the activity is the work of either the Russian special service or the actor of the threat agreed with Russia.

Cybersecurity

The company consists of four major phishing clusters representing itself for the Central Intelligence Agency (CIA), the Russian volunteer corps, the legion of Liberty and wanting “I want to live” and “a” a ” hotline For receiving appeals from members of the Russian service in Ukraine to give themselves to the Ukrainian armed forces.

It was found that the phishing pages are placed on the Nybula LLC hosting -piercing supplier, and the threat subjects are based on Google forms and e -mails to collect personal information, including their political views, bad habits and fitness, from the victims.

“All companies (…) observed – Note. “These phishing -anipotes are probably the work of either the Russian special service or the actor of the threat agreed with the Russian interests.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025

Learn the smarter way to protect modern applications

May 16, 2025

Meta to train AI on EU users since May 27 without consent; NOIB is threatened by lawsuits

May 15, 2025

Coinbase agents are bribed, data ~ 1% of users were traced; Attempted extortion of $ 20 million will not succeed

May 15, 2025

NPM malicious package uses Unicode Steganography, Google Calendar as C2 Chroper

May 15, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.