home.social

#certua — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #certua, aggregated by home.social.

fetched live
  1. In March, #CERTUA observed cyber-espionage attacks against Ukrainian state bodies and critical infrastructure by #UAC0219 spreading #WRECKSTEEL stealer for data theft. Detect potential intrusions with #Sigma rules from SOC Prime Platform.
    socprime.com/blog/detect-uac-0

  2. #CERTUA warns defenders about a targeted cyber-espionage operation by #UAC0200 targeting the Armed Forces of Ukraine. Detect associated malicious activity with #Sigma rules from SOC Prime Platform.
    socprime.com/blog/detect-uac-0

  3. #CERTUA warns defenders of a surge in phishing attacks by #UAC0173 against Ukrainian notaries to gain remote access and modify state registries. Detect increasing malicious activity with #Sigma rules from SOC Prime Platform.
    socprime.com/blog/detect-uac-0

  4. #CERTUA warns defenders of targeted activity to launch cyber-attacks against the critical infrastructure sector in Ukraine and beyond linked to UAC-0212, a subcluster of #Sandworm #APT. Detect intrusions with #Sigma rules from SOC Prime Platform.
    socprime.com/blog/detecting-ua

  5. #CERTUA warns defenders of #cyberattacks impersonating CERT-UA activity under the guise of security audits via #AnyDesk misuse. Detect relevant malicious activity and hosts using AnyDesk with curated #Sigma rules from SOC Prime Platform.
    socprime.com/blog/anydesk-expl

  6. #CERTUA alerts cyber defenders about new attacks on Ukraine by #UAC0125, using fake websites that imitate the "Army+" app page, hosted via Cloudflare Workers. Detect #cyberattacks with Sigma rules and explore campaign details on our blog.
    socprime.com/blog/uac-0125-att

    #cybersecurity

  7. #CERTUA warns of #UAC0185 (aka #UNC4221) attacks against Ukrainian Defense Forces and military-industrial sector. Detect associated malicious activity with a set of Sigma rules in the SOC Prime Platform. More insights in our blog!
    bit.ly/4imGM4d

  8. Two CERT-UA articles in 24 hours: The Computer Emergency Response Team of Ukraine warns that the Russian APT Sandworm (publicly attributed Unit 74455 of the Russian Main Intelligence Directorate (GRU) by the U.S. government) was planning to disrupt about 20 organizations in Ukraine's energy, water and heat supply industry in March 2024. They identified several malware strains during incident response, including new LOADGRIP and BIASBOAT (Linux variant of QUEUESEED malware). CERT-UA described the various malware. IOC provided. 🔗 cert.gov.ua/article/6278706

    #Sandworm #GRU #Russia #threatintel #cyberespionage #CERTUA #Ukraine #RussiaUkraineWar #IOC #UAC0133

  9. The Computer Emergency Response Team of Ukraine (CERT-UA) reported an attempted cyberattack against a Defense Forces of Ukraine representative. An unidentified threat actor (tracked as UAC-0149) used Signal messenger to send a malicious RAR archive for a job application. This leveraged the vulnerability CVE-2023-38831 (7.8 high, disclosed 23 August 2023 by Group-IB as an exploited zero-day; RARLAB WinRAR Code Execution Vulnerability). CERT-UA explained that the infection chain leads to COOKBOX malware being deployed. IOC provided. 🔗 cert.gov.ua/article/6278620

    #threatintel #cyberespionage #CERTUA #Ukraine #RussiaUkraineWar #IOC #UAC0149 #CVE_2023_38831

  10. The Computer Emergency Response Team of Ukraine (CERT-UA) reports that the threat actor group UAC-0184 is increasingly using popular messengers and social engineering in 2024 to target the Ukrainian military, and steal documents/messenger data (e.g. Signal). Malware delivered include IDAT, RemcosRAT, VIOTTOKEYLOGGER, XWorm, SIGTOP and TUSC. A lot of IOC provided, and images depict infection chains or lure messages. 🔗 (Ukrainian language) cert.gov.ua/article/6278521

    #CERTUA #UAC0184 #Ukraine #cyberespionage #threatintel #IOC #RemcosRAT #IDAT #xworm