• Russian hackers hit milit

    From Mike Powell@1:2320/105 to All on Friday, April 11, 2025 10:08:00
    Russian hackers hit military mission in Ukraine with info-stealing malware on external drives

    Date:
    Fri, 11 Apr 2025 11:00:00 +0000

    Description:
    The GammaSteel infostealer was found on infected devices belonging to a
    Western military operation in Ukraine.

    FULL STORY

    A military mission of a Western country, located in Ukraine, was the target
    of a Russian cyber-espionage attack according to cybersecurity researchers Symantec, who said they identified an attack that started in February 2025
    and likely continued until March.

    As per the researchers, the attack started with an infected removable drive. This device contained a malicious .LNK file that triggered an infection chain which resulted in the deployment of GammaSteel.

    GammaSteel is an infostealer malware , capable of exfiltrating documents in various formats, such as .DOCX, .PDF, .XLS, .TXT, and more. It was most
    likely built and deployed by a Russian state-sponsored threat actor known as Gamaredon (or Shuckworm).

    Infected removable drives

    Besides stealing files, it can also take screenshots of the infected device, and gather vital information about things like installed antivirus tools , running processes, and more.

    Finally, the tool establishes persistence on the compromised endpoints via a new Windows registry entry. The researchers said that the threat actors
    changed their tactics a bit to better hide the payload.

    Symantec did not say whose military mission was compromised, or what kind of information - if any - was stolen in the attack. It is safe to assume that
    the attack is part of a broader cyber-war effort since Russia invaded Ukraine more than three years ago.

    Russian aggression has shown just how much warfare changed and turned
    digital. The digital world became an entire front, with Russian
    cyber-infantry targeting communications satellites, government endpoints, electrical substations, and more.

    The Ukrainians responded by hacking Russian TV and radio to broadcast
    anti-war messages, manipulated a taxi app to send dozens of cars to a single location in Moscow, and leaked gigabytes of data from Russian entities, including the private military Wagner Group.

    Gamaredon is just one of many groups actively involved in the war, next to Conti, or Sandworm. All are apparently part of GRU, Russias military intelligence unit.

    Via BleepingComputer

    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/russian-hackers-hit-military-mission-in -ukraine-with-info-stealing-malware-on-external-drives

    $$
    --- SBBSecho 3.20-Linux
    * Origin: capitolcityonline.net * Telnet/SSH:2022/HTTP (1:2320/105)