Cybercriminals, pretending to be Ukrtelecom, spied on the state authorities of Ukraine

Cybercriminals, pretending to be Ukrtelecom, spied on the state authorities of Ukraine

Emails allegedly sent on behalf of Ukrtelecom contained files that launched a spyware program, reports the Government Computer Emergency Response Team of Ukraine CERT-UA.

We help

Unrecognizable

E-mails with the subject “Court claim against your personal account # 7192206443063763 dated: 06.02.2023” and an attachment in the form of a RAR archive “court letter, information about debt.rar” were received on the computers of employees of state authorities of Ukraine. The attachment contained a text document and another password-protected archive with an embedded file “court letter, debt information.pdf.exe” over 600 MB in size.

Cybercriminals, pretending to be Ukrtelecom, spied on Ukrainian authorities

When the file was launched, Remcos – a program for remote monitoring and surveillance from the BreakingSecurity company – was installed on the computer. It is usually used for legitimate remote administration, but in this case the hackers planned to spy on the victims’ computers.

Tame Power BI and predict the future of your company.

REGISTER!powerbi

“The detected activity has been tracked under UAC-0050 since at least 2020. Previous cyberattacks were carried out using the RemoteUtilities remote administration program. Based on the functionality of the programs and the fact that the objects of cyberattacks are usually the state authorities of Ukraine, it is considered that the attack is carried out for the purpose of espionage,” says CERT-UA.

Previously, cybercriminals already tried to steal data, masquerading as the Ministry of Foreign Affairs of Ukraine, as well as the State Emergency Service (using the theme of Iranian Shahed-136 kamikaze drones). In October-November 2022, similar letters also allegedly came from the State Special Communications, the press service of the General Staff of the Armed Forces of Ukraine, the Security Service of Ukraine, and from CERT-UA.

The developer pretended to be a hacker and demanded $2 million in cryptocurrency from his own company — he was exposed due to a VPN malfunction

Related Posts

Apple announced a “special event” on May 7 – expect new iPad Pro with OLED screen and 12.9-inch iPad Air

The Technology section is powered by Favbet Tech Apple has started sending media invitations to a “special event” featuring the Apple Pencil, hinting at the launch of…

The Google Pixel 8a smartphone first appeared in a video – it should be released on May 14

The Technology section is powered by Favbet Tech The presentation of the Google Pixel 8a smartphone is expected during Google I/O 2024 on May 14. The network…

Access to “Kyivstar TV” will be free in Kharkiv and the region with the promotional code KHARKIV

On April 22, Russian invaders damaged the television tower in Kharkiv. This caused problems with over-the-air television digital broadcasts (T2) in the region. In this regard, the…

Apple – no, Samsung can. South Korea to ban military iPhones for security reasons

The Technology section is powered by Favbet Tech According to The Korea Gerald, the South Korean military is considering a total ban on the use of Apple…

Embracer Group will be divided into three companies – one of them will belong to the Ukrainian 4A Games, which they wanted to sell to the Russians

Embracer Group has announced its intention to split into three different publicly traded gaming and entertainment companies. The new companies will be named Asmodee Group, Coffee Stain…

Vlad Yatsenko, Dmytro Zaporozhets and others. It became known which of the Ukrainian IT entrepreneurs earned the most

Vlad Yatsenko, co-founder of the Revolut service, topped the rating of Ukrainian IT entrepreneurs. He is followed by Dmytro Zaporozhets from GitLab and the team of top…

Leave a Reply

Your email address will not be published. Required fields are marked *