#Ukraine
15 stories taggedUkraine.

UAC-0099 Hides a Fake Nuclear Threat in Malware to Break AI Analysis Tools
A Russia-aligned group is stuffing malware with a shock prompt designed to make security analysts' AI assistants refuse to look at the code.

Manic Android malware hops between infected phones to steal Ukrainian banking data
Researchers at ThreatFabric say the spyware, active since February, targets 169 apps and can relay stolen data through nearby infected devices over Wi-Fi Direct or Bluetooth when the internet is unavailable.

Ukrainian police shut down 94 scam call centres, seize $2 million in cash
A joint operation with German investigators dismantled fake investment platforms and bank-impersonation scams targeting victims across the EU.

Fake Job Offers From Russian Hackers Target Ukrainian IT Staff
Ukraine's cyber emergency team says a Sandworm subgroup is posing as recruiters to slip remote-control malware onto engineers' laptops.

New Zealand Sanctions 33 Russia-Linked Cyber Operators and Child Abduction Networks
Wellington's latest penalties name hackers and individuals tied to the forced removal of Ukrainian children, signalling that digital warfare now sits alongside human-rights abuses on the sanctions list.

Ukraine warns of hackers hiding malware inside a fake Notepad++ plugin
CERT-UA links the campaign to UAC-0099, a group previously tied to Russia's Sandworm, which is using a genuine copy of Notepad++ to smuggle in a loader called LunchPoke.

Russian spies are hijacking Europe's security cameras to watch weapons move to Ukraine
Dutch intelligence says a Kremlin unit is quietly logging into internet-connected CCTV to track military convoys, aid shipments and troop positions.

Russian Military Hackers Trick Ukrainians Into Infecting Their Own PCs
Ukraine's cyber emergency team says a Sandworm sub-group is using fake CAPTCHA prompts to plant data-stealing malware.

US Treasury Sanctions VPN Provider Accused of Selling Cover to Ransomware Gangs
OFAC hits 1VPNS, its Ukrainian operator, and a malware cryptor seller, accusing them of helping ransomware crews attack American victims.

Your Business Is Already a Wartime Target. Here Is What to Do About It.
Nation-states attacking private companies is not a future risk. It happened at scale in 2017 and the conditions that made it possible have only grown more complicated since.

Gamaredon's 2025 Phishing Surge: 35 Campaigns, Fresh Loaders, and Identity Tradecraft
The Russia-aligned group has spent the year refining spear-phishing lures against Ukrainian targets, leaning harder on cloud services and credential theft.

SSU, FBI Detail Russian Phishing Op Targeting Signal and Telegram Accounts
Ukrainian counterintelligence says GRU and FSB-linked operators ran fake tech-support flows against officials' messengers across Ukraine, Europe, and the U.S.

Turla's STOCKSTAY: A Fresh .NET Backdoor Aimed at Kyiv and Rome
Google's threat hunters tie the Russian FSB-linked crew to a previously undocumented Windows implant hitting Ukrainian military targets and Italy-focused diplomatic entities.

Gamaredon Keeps Riding the WinRAR Path-Traversal Bug Into Ukrainian Endpoints
CVE-2025-8088 is months old and patched. The Russian crew is still landing GammaPhish, GammaWorm, and GammaSteel with it.

GREYVIBE: New Russian-Speaking Cluster Tied to Sustained Operations Against Ukraine
Researchers attribute an August 2025 campaign wave to a previously undocumented actor whose tasking patterns align with Kremlin interests.