home.social

#ukrainecyber — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #ukrainecyber, aggregated by home.social.

fetched live
  1. May 2026 Wave-2 Pterodo wrap:

    - 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
    - 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
    - 0 takedown responses from @no-ip on my abuse@ submissions
    - 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
    - Microsoft Defender remains the single mainstream AV reliably catching the HTML stage

    Active campaign. Quiet public reporting. The asymmetry is the story.

    Full notes: github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  2. May 2026 Wave-2 Pterodo wrap:

    - 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
    - 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
    - 0 takedown responses from @no-ip on my abuse@ submissions
    - 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
    - Microsoft Defender remains the single mainstream AV reliably catching the HTML stage

    Active campaign. Quiet public reporting. The asymmetry is the story.

    Full notes: github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  3. Looking for early reviewers on chapters 2 + 3 of my BSc thesis (Pterodo network architecture + WinRAR exploit chain).

    Project notes live at github.com/palianytsia-200/U-OB-KY. Draft PDFs available — DM here on Mastodon or email [email protected]. Happy to trade reviews (your DFIR / detection-engineering writeup for mine).

    Especially looking for anyone with hands-on Gamaredon incident-response experience. The thesis is methodology-heavy but I want feedback from people who've actually had to triage this stuff in a real SOC.

    #Pterodo #ThreatIntel #DFIR #UkraineCyber

  4. Looking for early reviewers on chapters 2 + 3 of my BSc thesis (Pterodo network architecture + WinRAR exploit chain).

    Project notes live at github.com/palianytsia-200/U-OB-KY. Draft PDFs available — DM here on Mastodon or email [email protected]. Happy to trade reviews (your DFIR / detection-engineering writeup for mine).

    Especially looking for anyone with hands-on Gamaredon incident-response experience. The thesis is methodology-heavy but I want feedback from people who've actually had to triage this stuff in a real SOC.

    #Pterodo #ThreatIntel #DFIR #UkraineCyber

  5. Looking for early reviewers on chapters 2 + 3 of my BSc thesis (Pterodo network architecture + WinRAR exploit chain).

    Project notes live at github.com/palianytsia-200/U-OB-KY. Draft PDFs available — DM here on Mastodon or email [email protected]. Happy to trade reviews (your DFIR / detection-engineering writeup for mine).

    Especially looking for anyone with hands-on Gamaredon incident-response experience. The thesis is methodology-heavy but I want feedback from people who've actually had to triage this stuff in a real SOC.

    #Pterodo #ThreatIntel #DFIR #UkraineCyber

  6. Looking for early reviewers on chapters 2 + 3 of my BSc thesis (Pterodo network architecture + WinRAR exploit chain).

    Project notes live at github.com/palianytsia-200/U-OB-KY. Draft PDFs available — DM here on Mastodon or email [email protected]. Happy to trade reviews (your DFIR / detection-engineering writeup for mine).

    Especially looking for anyone with hands-on Gamaredon incident-response experience. The thesis is methodology-heavy but I want feedback from people who've actually had to triage this stuff in a real SOC.

    #Pterodo #ThreatIntel #DFIR #UkraineCyber

  7. Looking for early reviewers on chapters 2 + 3 of my BSc thesis (Pterodo network architecture + WinRAR exploit chain).

    Project notes live at github.com/palianytsia-200/U-OB-KY. Draft PDFs available — DM here on Mastodon or email [email protected]. Happy to trade reviews (your DFIR / detection-engineering writeup for mine).

    Especially looking for anyone with hands-on Gamaredon incident-response experience. The thesis is methodology-heavy but I want feedback from people who've actually had to triage this stuff in a real SOC.

    #Pterodo #ThreatIntel #DFIR #UkraineCyber

  8. Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.

    UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.

    I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.

    github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  9. Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.

    UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.

    I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.

    github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  10. Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.

    14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.

    Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules

    #Pterodo #UAC0010 #UkraineCyber

  11. Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.

    14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.

    Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules

    #Pterodo #UAC0010 #UkraineCyber

  12. The CANFAIL campaign demonstrates structured, LLM-assisted phishing operations attributed to a suspected Russian-linked actor.

    Per Google Threat Intelligence Group:
    • Sectoral targeting: defense, military, energy, aerospace
    • Regionally tailored email list generation
    • Google Drive-hosted RAR payload delivery
    • Double-extension obfuscation (*.pdf.js)
    • JavaScript loader → PowerShell execution
    • Memory-only dropper
    • Fake error decoy
    • Links to PhantomCaptcha activity (via SentinelOne)

    LLMs were used for reconnaissance, lure generation, and post-compromise operational guidance.

    This signals operational AI integration into state-aligned cyber campaigns.

    Are detection models prepared for LLM-generated phishing artifacts?

    Engage below.
    Follow TechNadu for deep technical analysis.

    #ThreatIntel #CANFAIL #APTActivity #PhishingDetection #LLMThreats #PowerShellAbuse #UkraineCyber #C2Infrastructure #SOC #BlueTeam #CyberOperations #MalwareAnalysis #Infosec

  13. The CANFAIL campaign demonstrates structured, LLM-assisted phishing operations attributed to a suspected Russian-linked actor.

    Per Google Threat Intelligence Group:
    • Sectoral targeting: defense, military, energy, aerospace
    • Regionally tailored email list generation
    • Google Drive-hosted RAR payload delivery
    • Double-extension obfuscation (*.pdf.js)
    • JavaScript loader → PowerShell execution
    • Memory-only dropper
    • Fake error decoy
    • Links to PhantomCaptcha activity (via SentinelOne)

    LLMs were used for reconnaissance, lure generation, and post-compromise operational guidance.

    This signals operational AI integration into state-aligned cyber campaigns.

    Are detection models prepared for LLM-generated phishing artifacts?

    Engage below.
    Follow TechNadu for deep technical analysis.

    #ThreatIntel #CANFAIL #APTActivity #PhishingDetection #LLMThreats #PowerShellAbuse #UkraineCyber #C2Infrastructure #SOC #BlueTeam #CyberOperations #MalwareAnalysis #Infosec

  14. The CANFAIL campaign demonstrates structured, LLM-assisted phishing operations attributed to a suspected Russian-linked actor.

    Per Google Threat Intelligence Group:
    • Sectoral targeting: defense, military, energy, aerospace
    • Regionally tailored email list generation
    • Google Drive-hosted RAR payload delivery
    • Double-extension obfuscation (*.pdf.js)
    • JavaScript loader → PowerShell execution
    • Memory-only dropper
    • Fake error decoy
    • Links to PhantomCaptcha activity (via SentinelOne)

    LLMs were used for reconnaissance, lure generation, and post-compromise operational guidance.

    This signals operational AI integration into state-aligned cyber campaigns.

    Are detection models prepared for LLM-generated phishing artifacts?

    Engage below.
    Follow TechNadu for deep technical analysis.

    #ThreatIntel #CANFAIL #APTActivity #PhishingDetection #LLMThreats #PowerShellAbuse #UkraineCyber #C2Infrastructure #SOC #BlueTeam #CyberOperations #MalwareAnalysis #Infosec

  15. The CANFAIL campaign demonstrates structured, LLM-assisted phishing operations attributed to a suspected Russian-linked actor.

    Per Google Threat Intelligence Group:
    • Sectoral targeting: defense, military, energy, aerospace
    • Regionally tailored email list generation
    • Google Drive-hosted RAR payload delivery
    • Double-extension obfuscation (*.pdf.js)
    • JavaScript loader → PowerShell execution
    • Memory-only dropper
    • Fake error decoy
    • Links to PhantomCaptcha activity (via SentinelOne)

    LLMs were used for reconnaissance, lure generation, and post-compromise operational guidance.

    This signals operational AI integration into state-aligned cyber campaigns.

    Are detection models prepared for LLM-generated phishing artifacts?

    Engage below.
    Follow TechNadu for deep technical analysis.

    #ThreatIntel #CANFAIL #APTActivity #PhishingDetection #LLMThreats #PowerShellAbuse #UkraineCyber #C2Infrastructure #SOC #BlueTeam #CyberOperations #MalwareAnalysis #Infosec