Gamaredon Expands Ukraine Attacks with New Malware and Cloud Service Abuse
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
Russian APT group Gamaredon has continued its cyber onslaught against Ukraine throughout 2025, deploying new malware and increasingly abusing legitimate cloud services.…
The Security Service of Ukraine (SSU), in coordination with the U.S. Federal Bureau of Investigation (FBI), has uncovered a long-running cyber espionage…
OYSTERBLUES is an information stealer malware delivered via spear-phishing campaigns by UNC1151, targeting Ukrainian government organizations to exfiltrate sensitive data.
The Security Service of Ukraine (SSU) is the national security agency responsible for counterintelligence and cyber defense, which uncovered a Russian intelligence…
CERT-UA is the Computer Emergency Response Team of Ukraine, responsible for responding to cyber threats and attributing attacks, such as the UNC1151…
RomCom is a Russian hacking group that has exploited CVE-2025-8088, a WinRAR vulnerability, in attacks targeting Ukraine. They are known for cyber…
STOCKSTAY is a previously undocumented .NET backdoor used by the Russian threat actor Turla. It shares significant code overlaps with Kazuar and…
Google Threat Intelligence Group (GTIG) has attributed a previously undocumented .NET backdoor named STOCKSTAY to the Russian state-sponsored threat actor Turla. The…
Gamaredon is a Russian advanced persistent threat group that has been highly active against Ukrainian governmental and military institutions, using spear-phishing, custom…