#certua — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #certua, aggregated by home.social.
-
🇺🇦 🇷🇺 Ruská skupina útočí na ozbrojené síly Ukrajiny odkazy na „nadace“
https://infoek.cz/ruska-skupina-utoci-na-ozbrojene-sily-ukrajiny-odkazy-na-nadace-2026/
🇺🇦 🇷🇺 Russian group attacks Ukraine's armed forces, links to "foundations"
#CyberSecurity #Russia #Ukraine #StandWithUkraine #RussiaUkrainianWar #CERTUA #LaundryBear
-
UAC-0099 Attack Detection: Hackers Target Government and Defense Agencies in Ukraine Using MATCHBOIL, MATCHWOK, and DRAGSTARE Malware – Source: socprime.com https://ciso2ciso.com/uac-0099-attack-detection-hackers-target-government-and-defense-agencies-in-ukraine-using-matchboil-matchwok-and-dragstare-malware-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #socprimecom #socprime #CERT-UA #CERTUA #Blog
-
UAC-0001 (APT28) Attack Detection: The russia-Backed Actor Uses LLM-Powered LAMEHUG Malware to Target Security and Defense Sector – Source: socprime.com https://ciso2ciso.com/uac-0001-apt28-attack-detection-the-russia-backed-actor-uses-llm-powered-lamehug-malware-to-target-security-and-defense-sector-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #socprimecom #Phishing #socprime #CERT-UA #CERTUA #APT28 #Blog
-
UAC-0001 (APT28) Activity Detection: The russian State-Sponsored Group Targets Government Agencies Using BEARDSHELL and COVENANT Malware – Source: socprime.com https://ciso2ciso.com/uac-0001-apt28-activity-detection-the-russian-state-sponsored-group-targets-government-agencies-using-beardshell-and-covenant-malware-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #socprimecom #BEARDSHELL #COVENANT #socprime #CERT-UA #CERTUA #APT28 #Blog
-
Ukrainian Government Systems Targeted With Backdoors Hidden in Cloud APIs and Docs https://thecyberexpress.com/ukrainian-government-systems-targeted/ #UkrainianGovernmentSystems #TheCyberExpressNews #TheCyberExpress #FirewallDaily #CyberWarfare #MalwareNews #CyberNews #Espionage #FancyBear #Phishing #CERTUA #Russia #Signal #APT28 #APT28 #ICS
-
Ukraine Reports 48% Jump in Cyber Incidents in H2 2024, but 77% Drop in High-Severity Incidents https://thecyberexpress.com/cyber-incidents-in-h2-2024-ukraine/ #Ukrainecyberincident #TheCyberExpressNews #Ukrainecyberwarfare #Ukrainecyberattacks #VulnerabilityNews #malwareplaybook #TheCyberExpress #kineticattacks #FirewallDaily #CyberWarfare #ThreatActors #MalwareNews #CERTUkraine #GeoServer #Features #CERTUA
-
UAC-0226 Attack Detection: New Cyber-Espionage Campaign Targeting Ukrainian Innovation Hubs and Government Entities with GIFTEDCROOK Stealer – Source: socprime.com https://ciso2ciso.com/uac-0226-attack-detection-new-cyber-espionage-campaign-targeting-ukrainian-innovation-hubs-and-government-entities-with-giftedcrook-stealer-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #GIFTEDCROOK #socprimecom #Phishing #socprime #CERT-UA #UAC0226 #CERTUA #14303 #Blog
-
UAC-0219 Attack Detection: A New Cyber-Espionage Campaign Using a PowerShell Stealer WRECKSTEEL – Source: socprime.com https://ciso2ciso.com/uac-0219-attack-detection-a-new-cyber-espionage-campaign-using-a-powershell-stealer-wrecksteel-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #Latestthreats #socprimecom #WRECKSTEEL #Phishing #socprime #CERT-UA #UAC0219 #CERTUA #14283 #Blog
-
In March, #CERTUA observed cyber-espionage attacks against Ukrainian state bodies and critical infrastructure by #UAC0219 spreading #WRECKSTEEL stealer for data theft. Detect potential intrusions with #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/detect-uac-0219-attacks-against-ukrainian-state-bodies/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
#CERTUA warns defenders about a targeted cyber-espionage operation by #UAC0200 targeting the Armed Forces of Ukraine. Detect associated malicious activity with #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/detect-uac-0200-attacks-using-darkcrystal-rat/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
UAC-0200 Attack Detection: Cyber-Espionage Activity Targeting Defense Industry Sector and the Armed Forces of Ukraine Using DarkCrystal RAT – Source: socprime.com https://ciso2ciso.com/uac-0200-attack-detection-cyber-espionage-activity-targeting-defense-industry-sector-and-the-armed-forces-of-ukraine-using-darkcrystal-rat-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DarkCrystalRAT #DARKCRYSTALRAT #Latestthreats #socprimecom #socprime #CERT-UA #UAC0200 #CERTUA #14045 #Blog
-
Hackers Exploit RDP Tools to Breach Ukraine’s Notarial Offices, CERT-UA Reports https://thecyberexpress.com/uac-0173-cyberattack/ #StateSpecialCommunicationsService #MinistryofJusticeofUkraine #TheCyberExpressNews #UserAccountControl #TheCyberExpress #DataBreachNews #FirewallDaily #HackerNews #CyberNews #UAC0173 #CERTUA
-
UAC-0173 Activity Detection: Hackers Launch Phishing Attacks Against Ukrainian Notaries Using the DARKCRYSTALRAT Malware – Source: socprime.com https://ciso2ciso.com/uac-0173-activity-detection-hackers-launch-phishing-attacks-against-ukrainian-notaries-using-the-darkcrystalrat-malware-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #DARKCRYSTALRAT #Latestthreats #socprimecom #Phishing #socprime #CERT-UA #UAC0173 #CERTUA #13738 #Blog
-
#CERTUA warns defenders of a surge in phishing attacks by #UAC0173 against Ukrainian notaries to gain remote access and modify state registries. Detect increasing malicious activity with #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/detect-uac-0173-attacks-against-ukrainian-notaries/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
#CERTUA warns defenders of targeted activity to launch cyber-attacks against the critical infrastructure sector in Ukraine and beyond linked to UAC-0212, a subcluster of #Sandworm #APT. Detect intrusions with #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/detecting-uac-0212-attacks-linked-to-sandworm/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
Hackers Exploit AnyDesk Impersonating CERT-UA to Launch Cyber-Attacks – Source: socprime.com https://ciso2ciso.com/hackers-exploit-anydesk-impersonating-cert-ua-to-launch-cyber-attacks-source-socprime-com/ #ThreatDetectionMarketplace #rssfeedpostgeneratorecho #ThreatHuntingContent #CyberSecurityNews #DetectionContent #SOCPrimePlatform #Latestthreats #Cyberattack #socprimecom #socprime #CERT-UA #CERTUA #Sigma #Blog
-
#CERTUA warns defenders of #cyberattacks impersonating CERT-UA activity under the guise of security audits via #AnyDesk misuse. Detect relevant malicious activity and hosts using AnyDesk with curated #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/anydesk-exploitation-attack-detection/?utm_source=mastodon&utm_medium=social&utm_campaign=latest-threats&utm_content=blog-post -
#CERTUA alerts cyber defenders about new attacks on Ukraine by #UAC0125, using fake websites that imitate the "Army+" app page, hosted via Cloudflare Workers. Detect #cyberattacks with Sigma rules and explore campaign details on our blog.
https://socprime.com/blog/uac-0125-attacks-against-ukraine-detection/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
#CERTUA alerts on #UAC0099 cyber-espionage attacks against Ukrainian state bodies spreading LONEPAGE #malware. Detect adversary activity with curated #Sigma rules from SOC Prime Platform.
https://socprime.com/blog/uac-0099-cyber-espionage-attacks-detection/?utm_source=mastodon&utm_medium=social&utm_campaign=cert-ua&utm_content=blog-post -
#CERTUA warns of #UAC0185 (aka #UNC4221) attacks against Ukrainian Defense Forces and military-industrial sector. Detect associated malicious activity with a set of Sigma rules in the SOC Prime Platform. More insights in our blog!
https://bit.ly/4imGM4d -
UAC-0001 aka APT28 Attack Detection: Leveraging PowerShell Command in Clipboard as Initial Entry Point – Source: socprime.com https://ciso2ciso.com/uac-0001-aka-apt28-attack-detection-leveraging-powershell-command-in-clipboard-as-initial-entry-point-source-socprime-com/ #ThreatDetectionMarketplace #rssfeedpostgeneratorecho #ThreatHuntingContent #CyberSecurityNews #DetectionContent #SOCPrimePlatform #Latestthreats #Vulnerability #Cyberattack #socprimecom #Phishing #socprime #CERT-UA #CERTUA #Blog
-
UAC-0218 Attack Detection: Adversaries Steal Files Using HOMESTEEL Malware – Source: socprime.com https://ciso2ciso.com/uac-0218-attack-detection-adversaries-steal-files-using-homesteel-malware-source-socprime-com/ #ThreatDetectionMarketplace #rssfeedpostgeneratorecho #ThreatHuntingContent #CyberSecurityNews #DetectionContent #SOCPrimePlatform #Latestthreats #CERT-UA11717 #Cyberattack #socprimecom #socprime #CERT-UA #Malware #CERTUA #Sigma #Blog
-
Vermin Hackers Resurface to Target Ukrainian Defense Forces with SPECTR Malware https://thecyberexpress.com/vermin-hackers-resurface-target-ukraine-forces/ #UkrainianDefenseForces #TheCyberExpressNews #CybersecurityNews #CyberEssentials #TheCyberExpress #FirewallDaily #SpearPhishing #SPECTRMalware #VerminHackers #CyberWarfare #Espionage #Syncthing #Phishing #CERTUA #SPECTR
-
Russian Hackers Use Legit Remote Monitoring Software to Spy on Ukraine and Allies https://thecyberexpress.com/remote-monitoring-software-to-spy-on-ukraine/ #RemoteManagementSoftware #TheCyberExpressNews #CybersecurityNews #RemoteMonitoring #UkraineandAllies #TheCyberExpress #FirewallDaily #CyberWarfare #SmokeLoader #Hackers #malware #Ukraine #CERTUA #Europe #RMM #Spy #US
-
🇺🇦 Ukrainisches #CERT beschreibt Angriffe auf kritische Infrastruktur | Security https://www.heise.de/news/Ukrainisches-CERT-beschreibt-Angriffe-auf-kritische-Infrastruktur-9694865.html #CERTUA
-
Two CERT-UA articles in 24 hours: The Computer Emergency Response Team of Ukraine warns that the Russian APT Sandworm (publicly attributed Unit 74455 of the Russian Main Intelligence Directorate (GRU) by the U.S. government) was planning to disrupt about 20 organizations in Ukraine's energy, water and heat supply industry in March 2024. They identified several malware strains during incident response, including new LOADGRIP and BIASBOAT (Linux variant of QUEUESEED malware). CERT-UA described the various malware. IOC provided. 🔗 https://cert.gov.ua/article/6278706
#Sandworm #GRU #Russia #threatintel #cyberespionage #CERTUA #Ukraine #RussiaUkraineWar #IOC #UAC0133
-
The Computer Emergency Response Team of Ukraine (CERT-UA) reported an attempted cyberattack against a Defense Forces of Ukraine representative. An unidentified threat actor (tracked as UAC-0149) used Signal messenger to send a malicious RAR archive for a job application. This leveraged the vulnerability CVE-2023-38831 (7.8 high, disclosed 23 August 2023 by Group-IB as an exploited zero-day; RARLAB WinRAR Code Execution Vulnerability). CERT-UA explained that the infection chain leads to COOKBOX malware being deployed. IOC provided. 🔗 https://cert.gov.ua/article/6278620
#threatintel #cyberespionage #CERTUA #Ukraine #RussiaUkraineWar #IOC #UAC0149 #CVE_2023_38831
-
The Computer Emergency Response Team of Ukraine (CERT-UA) reports that the threat actor group UAC-0184 is increasingly using popular messengers and social engineering in 2024 to target the Ukrainian military, and steal documents/messenger data (e.g. Signal). Malware delivered include IDAT, RemcosRAT, VIOTTOKEYLOGGER, XWorm, SIGTOP and TUSC. A lot of IOC provided, and images depict infection chains or lure messages. 🔗 (Ukrainian language) https://cert.gov.ua/article/6278521
#CERTUA #UAC0184 #Ukraine #cyberespionage #threatintel #IOC #RemcosRAT #IDAT #xworm