Russia targets Ukrainian conscripts with Windows, Android malware

Russia

A hybrid espionage/influence campaign conducted by the Russian threat group ‘UNC5812’ has been uncovered, targeting Ukrainian military recruits with Windows and Android malware.

According to Google’s threat intelligence, the campaign impersonated a “Civil Defense” persona along with a website and dedicated Telegram channel to distribute malware through a fake recruitment avoidance app dubbed “Sunspinner” by the researchers.

The campaign targets Windows and Android devices using distinct malware for each platform, giving the attackers data theft and real-time spying capabilities.

Google has implemented protections to block the malicious activity, but the operation highlights Russia’s continued use and extensive capabilities in the cyber-warfare space.

Fake “Civil Defense” persona

UNC5812’s persona does not attempt to impersonate Ukraine’s Civil Defense or any government agencies but is instead promoted as a legitimate Ukraine-friendly organization that provides Ukrainian conscripts with helpful software tools and advice.

The persona uses a Telegram channel and a website to engage potential victims and deliver narratives against Ukraine’s recruitment and mobilization efforts, aiming to stir distrust and resistance among the population.

When Google discovered the campaign on September 18, 2024, the “Civil Defense” channel on Telegram had 80,000 members.

Civil Defense channel on Telegram
Civil Defense channel on Telegram
Source: Google

Users tricked into visiting Civil Defense’s website are taken to a download page for a malicious application promoted as a crowd-sourced mapping tool that can help users track the locations of recruiters, and avoid them.

Google calls this app “Sunspinner, and although the app features a map with markers, Google says the data is fabricated. The app’s only purpose is to hide the installation of malware that takes place in the background.

Malicious website spreading malware
Malicious website spreading malware
Source: Google

Dropping Windows and Android malware.

The fake apps offers Windows and Android downloads, and promises to add iOS and macOS soon, so Apple platforms are not supported yet.

The Windows download installs Pronsis Loader, a malware loader that fetches additional malicious payloads from UNC5812’s server, including the commodity info-stealer ‘PureStealer.’

PureStealer targets information stored in web browsers, like account passwords, cookies, cryptocurrency wallet details, email clients, and messaging app data.

On Android, the downloaded APK file drops CraxsRAT, also a commercially available backdoor.

CraxsRAT allows the attackers to track the victim’s location in real time, log their keystrokes, activate audio recordings, retrieve contact lists, access SMS messages, exfiltrate files, and harvest credentials.

To perform these malicious activities undeterred, the app tricks users into disabling Google Play Protect, Android’s in-built anti-malware tool, and manually grant it risky permissions.​

Video containing instructions on how to disable Play Protect
Instructional video on how to disable Play Protect
Source: Google

Google updated Google Play protections to detect and block the Android malware early and also added the domains and files associated with the campaign to its ‘Safe Browsing’ feature on Chrome.

The complete list of indicators of compromise associated with the latest UNC5812 campaign is available here.

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Samsung's patented L-shaped foldable display appears in stunning new smartphone concept renders thumbnail

Samsung’s patented L-shaped foldable display appears in stunning new smartphone concept renders

Reviews, News, CPU, GPU, Articles, Columns, Other "or" search relation.3D Printing, 5G, Accessory, AI, Alder Lake, AMD, Android, Apple, ARM, Audio, Biotech, Business, Camera, Cannon Lake, Cezanne (Zen 3), Charts, Chinese Tech, Chromebook, Coffee Lake, Comet Lake, Console, Convertible / 2-in-1, Cryptocurrency, Cyberlaw, Deal, Desktop, E-Mobility, Education, Exclusive, Fail, Foldable, Gadget, Galaxy Note, Galaxy S,…
Read More

On the opposite way! Tesla breaks record for electric car sales amid shortage of chips

A Tesla parece ser uma das empresas menos afetadas pela crise mundial de semicondutores. A empresa tecnológica e automobilística não diminui o ritmo e trabalha no Tesla Model 2, seu novo hatch elétrico acessível, além de apresentar o “Tesla Bot”, seu robô alimentado pela inteligência artificial utilizada nos veículos autônomos. À vista das inovações aparentemente…
Read More
Nigeria’s Central Bank raises interest rates to 27.50% thumbnail

Nigeria’s Central Bank raises interest rates to 27.50%

Nigeria’s Central Bank has raised interest rates to 27.5% in its final meeting of the year after inflation quickened in October. The monetary policy committee raised the benchmark interest rate by 25 basis points. “The considerations of the meeting were held on the backdrop of renewed inflationary pressures as the headline food and core measures rose
Read More
Is it worth swapping a OnePlus 9 Pro for a OnePlus 10 Pro? thumbnail

Is it worth swapping a OnePlus 9 Pro for a OnePlus 10 Pro?

Mas, como é que se compara contra o smartphone principal do ano passado, o OnePlus 9 Pro? Vale a pena trocar? Hoje (11 de Janeiro de 2022), o esperado OnePlus 10 Pro foi finalmente lançado na China. Esta é a mais recente estrela da companhia e é a variante mais poderosa da nova série OnePlus…
Read More
Cheaper, faster, lighter: This Japanese Windows 11 laptop will give the Surface Pro 9 a run for its money — but don't hold your breath if you want to buy one thumbnail

Cheaper, faster, lighter: This Japanese Windows 11 laptop will give the Surface Pro 9 a run for its money — but don’t hold your breath if you want to buy one

Japanese tech giant Dynabook has thrown down the gauntlet to Microsoft's Surface Pro 9 with its latest offering, the 13.3-inch full HD (1920 x 1080) convertible 2-in-1 Dynabook V83/LX, designed for business use.The new laptop features a 360-degree hinge, allowing it to be used in five different styles: Pen, Monitor, Note PC, Tablet, and Flat.
Read More

The Design and Implementation of the Wolfram Language Compiler (2020) [pdf]

6]endstream endobj 650 0 obj > /PTEX.FileName (/srv/ConfPub/tex/acm_artifacts_evaluated_functional.pdf) /PTEX.InfoDict 652 0 R /PTEX.PageNumber 1 /Resources > >> >> /Subtype /Form /Type /XObject /Length 7976 >> stream xœ}É®,;nÜçWԜ²DÍÛÞ0àE»—†F·/ŒªEÛÿ¾TVžá=‡ Eù–î–WOÓÿG±U³Ýþçï·úÏtûûÿþøë¿ýómܳœúíÿŽtûÿ¿ÿ>þý?ü‹tû¯#§Û¿Þþqóžþþ¿t{¼kãÞ[¿}äRïµÜ^7«v©8¥¶û´Ûóf­ÞלNé>XË •q_Ë@š÷4í ­Ž{²á´Yï­wlއHó>ÛbÏêËl·Ký>G)7ßÅiÜm–ý×é«0ë÷”ª“òš÷š+Hvo¹“Ô¹ «ùîKiø”ɧ´Rî+õƒ4uø°–¹['ù¾ÓÀ`5ÝWáø¾~[èÙ:7ç$0Åб–»ÍÅÁ,ßç|–ó}ŒrÌVŠ]géžËçuù²Æ*{õ $?ƒyÝ¡w_=_ÙÐʽÙ敷_ã°í ù*Èâ×3Ž2NK.‰¿ìóã^A9>r¿ç:/’àûÌ+ŸÂrùÂÊ=•vã”äs§vçJ‰l:—ã«q¦^ÛÞ{ê¾ý¹7}°Ý¸òÅÇtaÍ.¬«Îøºyv»|Ïy´*OrŸQvÅYëÓ9ºt›]Û™½|‰F!?.‚óþ蔮s -‚ïÉ ¨¹íq ŠóÒ¢W»Êüޖôb6~jyãÌ;Þ:FöÍ«"ž>µ‡°Ê'Žs:®ª¯ãdÇmÎ3ÿýƒùËí¯dÅ LuVg¥³pÐäˆ0|'¥û¦ëÝ9ë²Õ¼Ãfx4·Q)„jûf½“3=úF+†~œíåœÖÙ·ú¥¼ÇVûð{òøâkðeíÛ/ß%þsû›}¬V-»ýýÉÒFÏ«¥ÝÎY÷Üúa~6? ìÍoRlðãlk–“±õøçƒäq|’g'¼9° ç*OÞ}ÞÇÇÿmoãñã?¸SÍeí}àA˜®´Ía®{ónþóçŠÔò-¯{qγyÀ2tíè­ó4vە½c³êjþsí}Üjó¸cêýɹÔáËÒuÞ?Kµ­{ý²É LsSå“OW¸’aëÊ[ªÕzܦ›ŽMß亻ÁØ=£õÞd´Ýºç¹{¬¬ÕËÙÖ5óþä©ø²ð?Ú¢øOR/R}R8í{ãüå*ÕjïÍ'%6xŽp¶·Äm¤ |Ú÷øÇIxs`SÎ5j€¯› HÛØ'‘îÅ%Ë÷æv–úus?º26çV¸Â ;!ä¦WÉê–Ü­k†ßH°Éu ìdsQ“ËÎuŸÀ}lL:¼Ñü÷*Av|Æ¤éu_PAÂ7¯[C7Í•h(¯ûQ÷lÚÌô¢UÍ22d3RàNéys^ÊÇ£ù3¾½Öd¸|Sٖ÷wìàê„M¹CHöó }ҚºCR_ZC³$_2Ú`p[Ò2oœ`sö£i÷ìq÷çŸa§6x“?ºÎgÈÚ°…N³¡Y¦rtãæܛW4)Î@´á"È#2NÚÐržl&G/h׬ÁóR`Šì.&­ –bCX*А£Ê-©àškÇq¥Øl1_ÑÅa@8ð¾tꀡ$¸ðj²Cm?]çMŠޜt©¿¿È¯£ùz`ŽýßéÇ÷ÂaC¨@°Â!È-ñôŸb¶²JԞ¬ ¶,†øxTУ;œI™=šóJc…MŸ¡¯{oËrtÇ xs³>ºOCõiøµp®W¹ÉÞ Õ±üæÜpóàíÊý)†x`r€K:·ãÈ0¹×whx¢‰a´]e5@΅Àu7:œ°€ý·Þ¸ 4±eŠ(ú9Ür!¦ð_æ C»ôËhDû˜xÆÿÅ֝`RœÖy€Ð·o÷ë.1`kb®g‚çõ5: Ã8“˜ݰ1bp¼ZÜ°a)`fŒ‹p} q/Ì]üœ³bõÅxÓo6ÚFg;¸…ŸTgD¬Ã„Pªq¸]è×[ ÃJ&‹£îP>## ²8#Y«5W¦“ã!c:wù™JHfC®—v]úã§Ý8—嘝±^NXÍ+ž8R˜_ÿ°1þñ­êL‰wöõäÑEv8ÛÏ Ú Û1(ŒÐðSrç‘Ý`X—xØÎYHó&Ù4á&Æ†è¢ ñxàXiK¦[mº'PJÀ×øiêwïØiðú#Œ#×q’a‚ì$‚C,®ºUð&¶âÂwè{„Ø­yL ©nqì´1ôAÈò@ŠÃXhTÙô YÈ®ÉL8û0=q…¹(ÌÊô[OÂ| gbùíÔü  n^ pà&_7¬â¾húú­ …
Read More
Index Of News
Total
0
Share