Russia’s digital warriors adapt to support the war effort in Ukraine … – CyberScoop
Russian and pro-Russian operatives continue to modify their hacking and influence operations aimed at Ukraine to extract intelligence and sway public opinion in favor of the war, Google researchers said in a report released Wednesday. The latest tactics include promoting highly produced YouTube videos as well as more traditional phishing campaigns.
Roughly 14 months after the Russian invasion of Ukraine, the cyber components of the Russian onslaught continues with nearly 60% of Russian-backed phishing campaigns targeting Ukraine, Billy Leonard, a security engineer with the Google Threat Analysis Group, wrote in an update on the most notable hacking campaigns the company observed between January and March of 2023.
The latest report includes new information operations from Russias elite hacking units as well as work from a group believed to be Belarusian, a staunch Russian ally. From traditional credential and intelligence gathering efforts to information operations aimed abroad and at Russian audiences to glorify war efforts, the ongoing cyber operations remain active and show signs of adaptations and new techniques, Leonard wrote.
One of Russias most prolific and elite hacking groups known widely as Sandworm, but tracked by Google as FROZENBARENTS continues to focus heavily on the war in Ukraine with campaigns spanning intelligence collection, IO, and leaking hacked data through Telegram, Leonard wrote. Believed to operate out of Russian Armed Forces Main Directorate of the General Staff, or GRU, Unit 74455, the group known best for its multiple successful Ukrainian power grid attacks and the NotPetya malware that racked up more than $10 billion in global damages maintains its perch atop the Russian-backed offensive hacking ecosystem.
FROZENBARENTS remains the most versatile GRU cyber actor with offensive capabilities including credential phishing, mobile activity, malware, external exploitation of services, and beyond, Leonard wrote. They target sectors of interest for Russian intelligence collection including government, defense, energy, transportation/logistics, education, and humanitarian organizations.
The group continues to exploit EXIM mail servers around the world, Leonard wrote, a tactic it has employed since 2019, according to a 2020 NSA advisory. Once compromised, the hosts have been observed accessing victim networks, interacting with victim accounts, sending malicious emails, and engaged in information operations (IO) activity.
FROZENBARENTS has also continued to target organizations associated with the Caspian Pipeline Consortium (CPC), one of the largest oil pipelines in the world that transports crude oil from Kazakhstan across Russian territory to the Black Sea, Leonard wrote. The group has targeted a range of unnamed Eastern European energy sector organizations using fake Windows update packages on a domain spoofing CPC that, if executed, loaded a variation of the Rhadamanthys malware that could then exfiltrate stored credentials, including browser cookies.
Dating back to December 2022, the group has also launced multiple waves of credential theft campaigns targeting Ukrainian defense industry, military and Ukr.net mail users, Leonard wrote.
The group has also been active in the information operation space, he said, creating online personas to push pro-Russian news and narratives and leak stolen data, Leonard wrote, such as the persona CyberArmyofRussia, or CyberArmyofRussia_Reborn.
Both the YouTube channel for CyberArmyofRussia, or CyberArmyofRussia_Reborn which was pulled down upon notification and the Instagram account had minimal engagement and a negligible number of subscribers or followers, Leonard wrote. The groups Telegram channel, launched April 1, 2022, remains robust, with frequent posts for nearly 23,000 subscribers. Google researchers assess that the channel was created and controlled by the elite hacking unit.
In several recent incidents, FROZENBARENTS compromised a webserver of the target organization and uploaded a webshell to maintain persistent access to the compromised system, Leonard wrote. The attackers then deployed Adminer, a single file PHP script for managing databases, to exfiltrate data of interest. Shortly after exfiltration, the data appeared on the CyberArmyofRussia_Reborn Telegram channel.
In another information operation, the Internet Research Agency notorious for its efforts to shape domestic U.S. opinion ahead of the 2016 presidential elections produced a series of YouTube Shorts, short-form videos akin to TikTok or Instagrams Reels. The group has focused particularly on narratives supportive of Russia and the business interests of Russian oligarch Yevgeny Prigozhin, especially the Wagner Group, Leonard wrote.
The U.S. Department of Justice indicted Prigozhin, a longtime associate of Russian President Vladimir Putin, in 2018 for his role in the IRA interference operation. He is currently wanted by the FBI.
The group was also promoting a new film by Aurum LLC, a film company partially owned by Prigozhin. This movie has a high production value and communicates narratives portraying the Wagner Group in a positive light, Leonard wrote.
Altogether, Moscow continues to leverage the full spectrum of information operationsfrom overt state-backed media to covert platforms and accountsto shape public perception of the war in Ukraine, Leonard wrote.
Smaller campaigns from other hacking groups caught Googles eye as well.
Another operation attributed to the GRU as well but perhaps a unit other than FROZENBARENTS has since April 2022 maintained a Telegram channel to promote and amplify narratives related to the use of biological weapons in Ukraine and how the United States is responsible for the proliferation of biological weapons around the world, Leonard wrote. This campaign involves a Russian-language Telegram channel and an English Substack newsletter, which has published only once.
APT28 known widely as Fancy Bear, and tracked as FROZENLAKE sent multiple large waves of phishing emails to hundreds of users in Ukraine in February and March, Leonard wrote. Part of the effort involved reflected cross-site scripting (XSS) on multiple Ukrainian websites, which represents a new tactic for the group.
A Belarusian-linked hacking campaign tracked as PUSCHA by Google but sometimes called UNC1151 andlinked to Belarus by Mandiantin November 2021 has consistently targeted users in Ukraine and neighboring countries throughout the war, Leonard wrote, typically targeting the i.ua and meta.ua webmail services. Leonard described the phishing campaigns as targeted, and focused on small numbers of users in Ukraine.
Written by AJ VicensAJ covers nation-state threats and cybercrime. He was previously a reporter at Mother Jones. Get in touch via Signal/WhatsApp: (810-206-9411).
View post:
Russia's digital warriors adapt to support the war effort in Ukraine ... - CyberScoop
- The Campaign Ends at the Breach: Lessons from Ukraine on Why Armies Fail - warontherocks.com - April 8th, 2026 [April 8th, 2026]
- Ukraine Ramps Up Attacks on Russian Oil, Aiming to Curb Iran War Windfall - The New York Times - April 8th, 2026 [April 8th, 2026]
- Russia Boosts Oil Income to Highest Since Early in Ukraine War - Bloomberg.com - April 8th, 2026 [April 8th, 2026]
- A Flawed Formula for Peace in Ukraine: Trump Cant End a War With a Real Estate Transaction - Foreign Affairs - April 8th, 2026 [April 8th, 2026]
- Its essential for understanding what is going on in Ukraine: new exhibition explores wartime limb loss - The Art Newspaper - April 8th, 2026 [April 8th, 2026]
- Factbox-Ukraine Renews Attacks on Russian Energy Sites - What Has Been Hit? - U.S. News & World Report - April 8th, 2026 [April 8th, 2026]
- EU Delegations around the world show support to Ukraine - EEAS - April 8th, 2026 [April 8th, 2026]
- Moscow threatens Baltic states, claiming they help Ukraine strike Russia - Euronews.com - April 8th, 2026 [April 8th, 2026]
- Hungary Prepares For Elections As EU, Ukraine, And U.S. Await Results - Forbes - April 8th, 2026 [April 8th, 2026]
- Ukraine Warns Citizens to Avoid Traveling to Hungary Ahead of Elections Over Risk of Provocation Allegations - UNITED24 Media - April 8th, 2026 [April 8th, 2026]
- News Wrap: Russian strikes on southern Ukraine kill at least 4 - PBS - April 8th, 2026 [April 8th, 2026]
- Power cuts to be in effect in all regions of Ukraine this evening - Ukrinform - April 8th, 2026 [April 8th, 2026]
- Cameroon Reveals Death of 16 Citizens Fighting for Russia in Ukraine - UNITED24 Media - April 8th, 2026 [April 8th, 2026]
- Ukraine ready to reciprocate with ceasefire: Zelensky addresses Russia following truce between U.S. and Iran - Ukrinform - April 8th, 2026 [April 8th, 2026]
- Hardest war to solve, says JD Vance as US-led Russia-Ukraine peace push stalls over territory - WION - April 8th, 2026 [April 8th, 2026]
- Russias war casualty toll in Ukraine up by 1,030 over past day - Ukrinform - April 8th, 2026 [April 8th, 2026]
- Multiplex Ukraine To Receive International Exhibitor of the Year Award At CineEurope 2026 - Boxoffice Pro - April 8th, 2026 [April 8th, 2026]
- Cameroon confirms 16 nationals killed fighting for Russia in Ukraine [VIDEO] - TVP World - April 8th, 2026 [April 8th, 2026]
- Ukraine is using a World War I creeping barrage tactic to turn the tide of the war - We Are The Mighty - April 8th, 2026 [April 8th, 2026]
- Smell of war comes to St Petersburg as Ukraine hammers Russian refineries - Al Jazeera - April 7th, 2026 [April 7th, 2026]
- Mariia Vainshtein dreamed of going to America for college. The war in Ukraine brought her there sooner - Tennis.com - April 7th, 2026 [April 7th, 2026]
- Investing in Tomorrow: Strengthening Human Development and Resilience in Ukraine - worldbank.org - April 7th, 2026 [April 7th, 2026]
- Child rescued from rubble after Russia ramps up strikes on Ukraine - Al Jazeera - April 7th, 2026 [April 7th, 2026]
- Ukraine regains control of frontline areas in southeast and east, army chief says - Reuters - April 7th, 2026 [April 7th, 2026]
- Russia jails former Kursk governor in Ukraine incursion-linked graft probe - Al Jazeera - April 7th, 2026 [April 7th, 2026]
- Why Trees Are Key to Russias Spring Offensive in Ukraine - The New York Times - April 7th, 2026 [April 7th, 2026]
- With the World Focused on Iran, Ukraine Stuns Russia in the Mediterranean - Haaretz - April 7th, 2026 [April 7th, 2026]
- Tucson man extradited from Ukraine to face justice 32 years after fleeing conviction - KVOA - April 7th, 2026 [April 7th, 2026]
- Colin Dodd Homage to Ukraine - TheaterMania - April 7th, 2026 [April 7th, 2026]
- Ukraine Hits Major Oil Terminal in Southern Russia Moscow - The Moscow Times - April 7th, 2026 [April 7th, 2026]
- How the Ukraine and Iran Wars Became Intertwined - The National Interest - April 7th, 2026 [April 7th, 2026]
- Russia says 'highly likely' that Ukraine planted explosives near gas pipeline - France 24 - April 7th, 2026 [April 7th, 2026]
- A long Mideast war could take away from support for Ukraine, Zelenskyy tells the AP - Aurora Sentinel - April 7th, 2026 [April 7th, 2026]
- The Lifeline Burns: Ukraine Takes Aim at the Heart of Russias Oil Empire - Space Daily - April 7th, 2026 [April 7th, 2026]
- For the First Time, Ukraine Outguns Russia in Long-Range Drone Attacks - UNITED24 Media - April 7th, 2026 [April 7th, 2026]
- A long Mideast war could take away from support for Ukraine, Zelenskyy tells the AP - AP News - April 7th, 2026 [April 7th, 2026]
- Japan's aid to Ukraine harms ties with Russia: foreign ministry - news.cgtn.com - April 7th, 2026 [April 7th, 2026]
- Russia issues veiled threats to Baltic states over Ukraine airspace claims they have long denied - kyivindependent.com - April 7th, 2026 [April 7th, 2026]
- Ukraine faces balancing act as it seeks to build ties with Syria - thenationalnews.com - April 7th, 2026 [April 7th, 2026]
- Ukraine may be using new weapon that disables infrastructure without explosions - Euromaidan Press - April 7th, 2026 [April 7th, 2026]
- Why Orbn needs Ukraine Zelensky is the perfect scapegoat - UnHerd - April 7th, 2026 [April 7th, 2026]
- Ukraine war briefing: Slovakia PM calls on EU to lift sanctions on Russian oil and gas - The Guardian - April 5th, 2026 [April 5th, 2026]
- A long Mideast war could take away from support for Ukraine, Zelenskyy tells the AP - The Boston Globe - April 5th, 2026 [April 5th, 2026]
- How Russia is taking advantage of the Iran war to pummel Ukraine - The Times - April 5th, 2026 [April 5th, 2026]
- Ukraine asked to ease attacks on Russian oil refineries amid Iran war price surge, Budanov says - The Kyiv Independent - April 5th, 2026 [April 5th, 2026]
- Russia and Ukraine trade deadly strikes as Zelenskyy travels to Istanbul for talks with Erdogan - Yahoo - April 5th, 2026 [April 5th, 2026]
- At least 15 killed in Russian attacks on Ukraine as Zelenskyy meets Erdogan - aljazeera.com - April 5th, 2026 [April 5th, 2026]
- Russia and Ukraine trade deadly strikes as Zelenskyy travels to Istanbul for talks with Erdogan - TelegraphHerald.com - April 5th, 2026 [April 5th, 2026]
- Ukraine war briefing: Russian army records almost no territorial gains for first time since 2023, analysis shows - The Guardian - April 5th, 2026 [April 5th, 2026]
- Zelenskiy says frontline situation best for Ukraine in the last 10 months - Reuters - April 5th, 2026 [April 5th, 2026]
- The frontline is like Terminator: fighting robots give Ukraine hope in war with Russia - The Guardian - April 5th, 2026 [April 5th, 2026]
- Russia loses 1,180 troops in war against Ukraine over past day - Ukrinform - Ukrainian National News Agency - April 5th, 2026 [April 5th, 2026]
- Why Israel and Ukraine Irritate the World, or The Geopolitics of Loneliness - The Times of Israel - April 5th, 2026 [April 5th, 2026]
- Ukraine boosts farm equipment compensation to 40% for farmers in war-affected areas - Ukrinform - Ukrainian National News Agency - April 5th, 2026 [April 5th, 2026]
- Ukraine extradites foreign fighter who fought for Russia to Azerbaijan - Ukrinform - Ukrainian National News Agency - April 5th, 2026 [April 5th, 2026]
- Russia attacks Ukraine with nearly 100 drones: hits recorded at 10 locations - Yahoo - April 5th, 2026 [April 5th, 2026]
- Can Ukraine help reopen the Strait of Hormuz? Here's what Zelensky can offer - The Kyiv Independent - April 5th, 2026 [April 5th, 2026]
- President Discussed Support for Ukraine and Efforts to Achieve a Dignified Peace with Ecumenical Patriarch Bartholomew Official website of the... - April 5th, 2026 [April 5th, 2026]
- Ukraine restores nearly half of power generation wiped out by Russia - The Kyiv Independent - April 5th, 2026 [April 5th, 2026]
- Ukraine: 128 clashes with Russia in past 24 hours - Breakingthenews.net - April 5th, 2026 [April 5th, 2026]
- Delegation led by Witkoff and Kushner may visit Ukraine after Easter Budanov - Ukrinform - Ukrainian National News Agency - April 5th, 2026 [April 5th, 2026]
- During a Meeting in Istanbul, the Presidents of Ukraine and Trkiye Discussed Strengthening Cooperation in the Areas of Security and Energy - - - April 5th, 2026 [April 5th, 2026]
- Ukraine hits key Russian plant in occupied Luhansk second time in month, grinding production to halt - The Kyiv Independent - April 5th, 2026 [April 5th, 2026]
- Ukraine war briefing: Zelenskyy says US has linked security guarantees to ceding of Donbas - The Guardian - March 26th, 2026 [March 26th, 2026]
- Welcome to 'New Russia': How the Kremlin is remaking occupied Ukraine - The Detroit News - March 26th, 2026 [March 26th, 2026]
- Iran war deflects attention from Ukraine as an emboldened Russia starts spring offensive - abcnews.com - March 26th, 2026 [March 26th, 2026]
- In Rural Ukraine, Basic Health Care Is a Casualty of War - The New York Times - March 26th, 2026 [March 26th, 2026]
- Trump pressuring Ukraine to cede territory to Russia, Zelenskyy says - politico.eu - March 26th, 2026 [March 26th, 2026]
- Welcome to New Russia: How the Kremlin is remaking occupied Ukraine - Reuters - March 26th, 2026 [March 26th, 2026]
- G7 allies meet against backdrop of wars in Ukraine and Iran, with unpredictable US - Reuters - March 26th, 2026 [March 26th, 2026]
- Russia says it hopes for new round of Ukraine talks with US as soon as conditions allow - The Detroit News - March 26th, 2026 [March 26th, 2026]
- Ukraine Spent Big to Shield Energy Industry From Drones. Is the Mideast Next? - The New York Times - March 26th, 2026 [March 26th, 2026]
- The Coming Drone-War Inflection in Ukraine - IEEE Spectrum - March 26th, 2026 [March 26th, 2026]
- Russia fires more than 1,000 drones against Ukraine as spring offensive ramps up on battlefield - CNN - March 26th, 2026 [March 26th, 2026]
- Estonia and Latvia say drones hit their NATO territory as Ukraine and Russia traded attacks - CBS News - March 26th, 2026 [March 26th, 2026]
- US security guarantees tied to Ukraine's withdrawal from Donbas, Zelensky says - The Kyiv Independent - March 26th, 2026 [March 26th, 2026]
- Ukraine faces new Russian offensive as peace talks stall - Reuters - March 26th, 2026 [March 26th, 2026]
- Ukraine's unique role in the Iran war: From the Politics Desk - NBC News - March 26th, 2026 [March 26th, 2026]
- Ukraine: four years of heartache - Anabaptist World - March 26th, 2026 [March 26th, 2026]
- Russian forces begin offensive in Ukraine as Zelensky worries about impact of Iran conflict - CNN - March 26th, 2026 [March 26th, 2026]