Close Menu
  • Home
  • Android
  • Android Operating
  • Apple
  • Apps
  • Gadgets
  • Galaxy
  • Ipad
  • IPhone
  • Smartphone
  • Tablet

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

Muse Dash, Hyperforma, Tower of Fortune 4, etc.

March 28, 2025

Best Kitchen Gadgets of 2025

March 18, 2025

The best drawing tablets of 2025: Expert tested and recommended

February 13, 2025
Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
Facebook X (Twitter) Instagram
Wtf AndroidWtf Android
  • Home
  • Android
  • Android Operating
  • Apple
  • Apps
  • Gadgets
  • Galaxy
  • Ipad
  • IPhone
  • Smartphone
  • Tablet
Wtf AndroidWtf Android
Home » Russia targets Ukrainian military with impersonated recruitment app
Apps

Russia targets Ukrainian military with impersonated recruitment app

adminBy adminOctober 28, 2024No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest Email


Ukraine is facing a two-pronged cyber attack by Kremlin-backed actors as it seeks to recruit new soldiers to join its war against Russia.

Researchers from Google’s Threat Intelligence Group (TAG) and Mandiant used a spoofed version of the legitimate Ukrainian tool Civil Defense, a crowd-sourced mapping tool used to find military recruiters. tracked active campaigns. Attackers use fake versions to perform dual malicious actions: dropping malware and distributing false information.

The hybrid operation, dubbed UNC5812 by researchers, uses Telegram channels to lure new employees into downloading a malicious version of Civil Defense from a spoofed site outside of Google Play. Once downloaded, the application drops Windows and Android malware.

Russian OPP uses malware with social engineering aspects

Windows users who visited a fake Civil Defense site to download the tool were delivered Pronsis Loader, which then began a chain that distributed a malicious mapping application called Sunspinner and an information stealer called Purestealer. will be done.

Meanwhile, Android users get a popular user backdoor called Craxsrat in addition to Sunspinner.

“Notably, the Civil Defense website contains unconventional content aimed at pre-empting user skepticism about APK distribution outside the App Store and justifying the extensive permissions required to install Craxsrat. and forms of social engineering,” the report said. “The website’s FAQ includes a harsh justification that Android applications are hosted outside of the App Store, suggesting this is an effort to ‘protect the anonymity and security’ of users. and are guided through the accompanying video instructions.

This video also explains how to disable Google Play Protect.

“While the Civil Defense website also advertises support for macOS and iPhone, only Windows and Android payloads were available at the time of analysis,” the report said.

Sunspinner, a decoy graphical user interface (GUI) application created using the Flutter framework, provides functionality aimed at convincing victims that the application is legitimate.

“Consistent with the features advertised above. [legitimate] According to Google TAG analysis, civil defense website Sunspinner can display crowd-sourced markers for the locations of Ukrainian military recruits, with an option for users to add their own markers. ” But fake maps only provide fake locations. , despite having the limited functionality required for users to register and add markers, the displayed map does not appear to contain any genuine user input. all markers are present [were pulled from the attacker’s C2 and] Added by the same user on the same day. ”

In parallel with counter-mobilization operations against the Ukrainian military

In parallel with espionage, another objective of Russia’s fake civil defense campaign is the dissemination of disinformation aimed at suppressing Ukraine’s military mobilization efforts for war. Civil Defense sites and malicious versions of Telegram pushed out videos with inflammatory and anti-Ukrainian military titles such as “Unjust acts from the territorial recruitment center.” TAG Mandiant Report Added.

“Users who click on the ‘Submit Materials’ button provided by a site run by Russian hackers are automatically sent to a chat thread controlled by the attackers, ostensibly to discredit the recruitment effort,” the report said. states. The group’s website and Telegram channel appear to be informed by the broader pro-Russian social media ecosystem. In at least one instance, a video shared by UNC5812 was shared a day later by the Russian embassy’s X account in South Africa. ”

Russia has consistently used cyber attacks. War strategy against Ukraineand other governments as well, including the recent Distributed Denial of Service (DDoS). Cyber ​​attack campaign against Japanese loading ports. Russian hackers are also hard at work distributing Disinformation ahead of the 2024 US election. This threat group is currently considered the most active and direct supporter of military operations in Russia. Ukraine is a sandwormbut as this newly revealed “civil defense” campaign highlights, it’s just one of many hacker groups doing the Kremlin’s dirty work in cyberspace.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
admin
  • Website

Related Posts

Muse Dash, Hyperforma, Tower of Fortune 4, etc.

March 28, 2025

New Android spyware warning – don’t install these apps

October 31, 2024

Google Apps Finally Adds Material 3 Bottom Bar to Android

October 31, 2024
Add A Comment
Leave A Reply Cancel Reply

Editors Picks

Will Google’s new anti-theft feature be a game-changer for Android users?

October 13, 2024

Huawei’s Android replacement HarmonyOS Next launches next week, permanently discontinuing Google’s operating system on existing devices

October 11, 2024

Android 15 lets you turn your phone into a useful smart home dashboard – here’s how

October 11, 2024

Google ordered to open Android app store to competition

October 10, 2024
Top Reviews
Wtf Android
Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact us
  • DMCA Policy
  • Privacy Policy
  • Terms & Conditions
© 2025 wtfandroid. Designed by wtfandroid.

Type above and press Enter to search. Press Esc to cancel.