Site navigation

Russia/Ukraine-themed War Docs are now a Popular Cyber-lure

Graham Turner

,

Russia-ukraine cyber-lures
Check Point Research (CPR) warns of threat groups worldwide using Russia/Ukraine-themed war documents to spread malware and lure victims into cyber espionage.

Depending on the targets and region, attackers are using decoys ranging from official-looking documents, to news articles and job postings related to the conflict in the Ukraine.

CPR believes the motivation behind these recent campaigns is cyber espionage, to steal sensitive information from governments, banks and energy companies. The threat groups and their victims are not concentrated to one region, but span worldwide, including Latin America, the Middle East and Asia.

In a new publication, CPR profiles three APT groups, named El Machete, Lyceum and Sidewinder, who were recently caught conducting the spear-phishing campaigns on victims in five countries.

The malware laced by each of the three APT groups, specifically for these cyber espionage activities have been found to have myriad capabilities, including keylogging, credential collection, file collection, screenshotting, clipboard data collection and command execution.

Attack methodologies between the three groups range but share a commonality in that they all start with a document or an email containing text about the Ukraine or the conflict in general.

Talking about this latest threat, Sergey Shykevich, Threat Intelligence Group Manager at Check Point Software, said: “Right now, we are seeing a variety of APT campaigns that utilizes the current war for malware distribution.

“The campaigns are highly targeted and sophisticated, focusing on victims in the government, financial and energy sectors. In our newest report, we profile and bring examples from three different APT groups, who all originate in different parts of the world, that we caught orchestrating these spear-phishing campaigns.

“We studied the malware involved closely, and found capabilities that span keylogging, screenshotting and more. It is my strong belief that these campaigns are designed with the core motivation of cyber espionage. Our findings reveal a clear trend, that collateral around the war between Russia and Ukraine has become a lure of choice for threat groups world-wide.


Recommended


“I strongly recommend governments, banks and energy companies to reiterate cyber awareness and education to employees, and to implement cyber security solutions that protect the network on all levels.”

Recently, Check Point Research released an update on cyber-attack trends throughout the current Russia-Ukraine war.

One month after the war started on 24th February 2022, both Russia and Ukraine saw increases in cyber-attacks of 10% and 17% respectively.

CPR has also observed a 16% increase in cyber-attacks globally throughout the current conflict. CPR shared cyber-attack data for NATO countries, regions and more here.


Get the latest news from DIGIT direct to your inbox

Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.

To subscribe, click here.

Graham Turner

Sub Editor

Latest News

Cybersecurity Editor's Picks

OpenAI Flags Potential ‘Critical’ Cyber Risk From Astra

Business Featured Funding

VC Access Expanded For Early-stage Companies in UK

Business Editor's Picks Technology

Comment | Managing Risk in Multi-Supplier SaaS Procurements

AI Recruitment Skills

Young Scots Seek Jobs That AI Can’t Replace