Russia’s digital warriors adapt to support the war effort in Ukraine … – CyberScoop
Russian and pro-Russian operatives continue to modify their hacking and influence operations aimed at Ukraine to extract intelligence and sway public opinion in favor of the war, Google researchers said in a report released Wednesday. The latest tactics include promoting highly produced YouTube videos as well as more traditional phishing campaigns.
Roughly 14 months after the Russian invasion of Ukraine, the cyber components of the Russian onslaught continues with nearly 60% of Russian-backed phishing campaigns targeting Ukraine, Billy Leonard, a security engineer with the Google Threat Analysis Group, wrote in an update on the most notable hacking campaigns the company observed between January and March of 2023.
The latest report includes new information operations from Russias elite hacking units as well as work from a group believed to be Belarusian, a staunch Russian ally. From traditional credential and intelligence gathering efforts to information operations aimed abroad and at Russian audiences to glorify war efforts, the ongoing cyber operations remain active and show signs of adaptations and new techniques, Leonard wrote.
One of Russias most prolific and elite hacking groups known widely as Sandworm, but tracked by Google as FROZENBARENTS continues to focus heavily on the war in Ukraine with campaigns spanning intelligence collection, IO, and leaking hacked data through Telegram, Leonard wrote. Believed to operate out of Russian Armed Forces Main Directorate of the General Staff, or GRU, Unit 74455, the group known best for its multiple successful Ukrainian power grid attacks and the NotPetya malware that racked up more than $10 billion in global damages maintains its perch atop the Russian-backed offensive hacking ecosystem.
FROZENBARENTS remains the most versatile GRU cyber actor with offensive capabilities including credential phishing, mobile activity, malware, external exploitation of services, and beyond, Leonard wrote. They target sectors of interest for Russian intelligence collection including government, defense, energy, transportation/logistics, education, and humanitarian organizations.
The group continues to exploit EXIM mail servers around the world, Leonard wrote, a tactic it has employed since 2019, according to a 2020 NSA advisory. Once compromised, the hosts have been observed accessing victim networks, interacting with victim accounts, sending malicious emails, and engaged in information operations (IO) activity.
FROZENBARENTS has also continued to target organizations associated with the Caspian Pipeline Consortium (CPC), one of the largest oil pipelines in the world that transports crude oil from Kazakhstan across Russian territory to the Black Sea, Leonard wrote. The group has targeted a range of unnamed Eastern European energy sector organizations using fake Windows update packages on a domain spoofing CPC that, if executed, loaded a variation of the Rhadamanthys malware that could then exfiltrate stored credentials, including browser cookies.
Dating back to December 2022, the group has also launced multiple waves of credential theft campaigns targeting Ukrainian defense industry, military and Ukr.net mail users, Leonard wrote.
The group has also been active in the information operation space, he said, creating online personas to push pro-Russian news and narratives and leak stolen data, Leonard wrote, such as the persona CyberArmyofRussia, or CyberArmyofRussia_Reborn.
Both the YouTube channel for CyberArmyofRussia, or CyberArmyofRussia_Reborn which was pulled down upon notification and the Instagram account had minimal engagement and a negligible number of subscribers or followers, Leonard wrote. The groups Telegram channel, launched April 1, 2022, remains robust, with frequent posts for nearly 23,000 subscribers. Google researchers assess that the channel was created and controlled by the elite hacking unit.
In several recent incidents, FROZENBARENTS compromised a webserver of the target organization and uploaded a webshell to maintain persistent access to the compromised system, Leonard wrote. The attackers then deployed Adminer, a single file PHP script for managing databases, to exfiltrate data of interest. Shortly after exfiltration, the data appeared on the CyberArmyofRussia_Reborn Telegram channel.
In another information operation, the Internet Research Agency notorious for its efforts to shape domestic U.S. opinion ahead of the 2016 presidential elections produced a series of YouTube Shorts, short-form videos akin to TikTok or Instagrams Reels. The group has focused particularly on narratives supportive of Russia and the business interests of Russian oligarch Yevgeny Prigozhin, especially the Wagner Group, Leonard wrote.
The U.S. Department of Justice indicted Prigozhin, a longtime associate of Russian President Vladimir Putin, in 2018 for his role in the IRA interference operation. He is currently wanted by the FBI.
The group was also promoting a new film by Aurum LLC, a film company partially owned by Prigozhin. This movie has a high production value and communicates narratives portraying the Wagner Group in a positive light, Leonard wrote.
Altogether, Moscow continues to leverage the full spectrum of information operationsfrom overt state-backed media to covert platforms and accountsto shape public perception of the war in Ukraine, Leonard wrote.
Smaller campaigns from other hacking groups caught Googles eye as well.
Another operation attributed to the GRU as well but perhaps a unit other than FROZENBARENTS has since April 2022 maintained a Telegram channel to promote and amplify narratives related to the use of biological weapons in Ukraine and how the United States is responsible for the proliferation of biological weapons around the world, Leonard wrote. This campaign involves a Russian-language Telegram channel and an English Substack newsletter, which has published only once.
APT28 known widely as Fancy Bear, and tracked as FROZENLAKE sent multiple large waves of phishing emails to hundreds of users in Ukraine in February and March, Leonard wrote. Part of the effort involved reflected cross-site scripting (XSS) on multiple Ukrainian websites, which represents a new tactic for the group.
A Belarusian-linked hacking campaign tracked as PUSCHA by Google but sometimes called UNC1151 andlinked to Belarus by Mandiantin November 2021 has consistently targeted users in Ukraine and neighboring countries throughout the war, Leonard wrote, typically targeting the i.ua and meta.ua webmail services. Leonard described the phishing campaigns as targeted, and focused on small numbers of users in Ukraine.
Written by AJ VicensAJ covers nation-state threats and cybercrime. He was previously a reporter at Mother Jones. Get in touch via Signal/WhatsApp: (810-206-9411).
View post:
Russia's digital warriors adapt to support the war effort in Ukraine ... - CyberScoop
- Trumps Ukraine ceasefire is slipping away - The Economist - April 16th, 2025 [April 16th, 2025]
- Truth, lies and the betrayal of Ukraine - Financial Times - April 16th, 2025 [April 16th, 2025]
- JD Vance offers message to Europe on security, Ukraine and Trump's tariffs in interview with U.K. outlet - CBS News - April 16th, 2025 [April 16th, 2025]
- 'Everybody's to blame': Trump accuses Zelenskyy of starting Russia's war on Ukraine - USA Today - April 16th, 2025 [April 16th, 2025]
- Zelensky urges Trump to visit Ukraine ahead of deal with Russia - BBC - April 16th, 2025 [April 16th, 2025]
- Bulgaria unexpectedly rejects sale of Russian nuclear reactors to Ukraine - Euractiv - April 16th, 2025 [April 16th, 2025]
- Bogged down in east Ukraine, Putins Russia eyes opportunistic gains in northern Sumy - France 24 - April 16th, 2025 [April 16th, 2025]
- On the Way of the Cross, in Ukraine and Hong Kong - National Catholic Register - April 16th, 2025 [April 16th, 2025]
- Grading Trumps Ukraine War deal-making by Art of the Deal standards - The Hill - April 16th, 2025 [April 16th, 2025]
- North Korea soldiers, weapons helped Russia at critical moment in war on Ukraine - Reuters - April 16th, 2025 [April 16th, 2025]
- Russia says it is not easy to agree Ukraine peace deal with US - Reuters - April 16th, 2025 [April 16th, 2025]
- Trump's Ukraine peace push is really about business and Putin knows it - The Kyiv Independent - April 16th, 2025 [April 16th, 2025]
- Russia and Belarus ready to act over 'European escalation' around Ukraine, Kremlin spy chief says - NBC News - April 16th, 2025 [April 16th, 2025]
- Rubio, Witkoff to travel to France this week for Ukraine talks. - The Kyiv Independent - April 16th, 2025 [April 16th, 2025]
- Rubio, Witkoff heading to France for talks on Ukraine, Iran and trade - politico.eu - April 16th, 2025 [April 16th, 2025]
- Ukraine's DIY drone makers are helping fighters on the front lines - NPR - April 16th, 2025 [April 16th, 2025]
- Russia claims its deadly attack on Ukraine's Sumy targeted military forces as condemnation grows - AP News - April 16th, 2025 [April 16th, 2025]
- Ukraine war: Russians are even trying to ban our holidays' - life in occupied territories - BBC - April 16th, 2025 [April 16th, 2025]
- Michael Clarke Ukraine war Q&A: Has Trump tripped up? Why's he saying Zelenskyy started war? What message is Putin giving world? - Sky News - April 16th, 2025 [April 16th, 2025]
- Prince William "Fuming" at Palace Officials Because Prince Harry Went to Ukraine - Cosmopolitan - April 16th, 2025 [April 16th, 2025]
- Ukraine war briefing: Captive Chinese soldiers appear before the press in Kyiv - The Guardian - April 16th, 2025 [April 16th, 2025]
- US military aid for Ukraine is about to cease. Is Europe ready? | David Shimer - The Guardian - April 16th, 2025 [April 16th, 2025]
- Ukraine's Zelenskyy says the security of the world is at stake amid Russia war: "The threat is real" - CBS News - April 16th, 2025 [April 16th, 2025]
- Zelenskyy urges Trump to view devastation in Ukraine caused by Russias invasion - The Guardian - April 16th, 2025 [April 16th, 2025]
- Ukraine Breaking News Today Live on 04-16-2025 - Kyiv Post - April 16th, 2025 [April 16th, 2025]
- US demands control from Ukraine of key pipeline carrying Russian gas - The Guardian - April 16th, 2025 [April 16th, 2025]
- Zelensky confirms Ukraine troops active in Russia's Belgorod region - BBC - April 8th, 2025 [April 8th, 2025]
- Ukraine war briefing: Zelenskyy speaks of military presence in Russias Belgorod region for first time - The Guardian - April 8th, 2025 [April 8th, 2025]
- Trump 'not happy' with Russian bombing of Ukraine, says he 'doesn't know what's happening there' - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- Ukraine braces for Russian offensive ahead of negotiations - DW - April 8th, 2025 [April 8th, 2025]
- Ukraine will send a team to the US next week for talks on a new draft mineral deal - AP News - April 8th, 2025 [April 8th, 2025]
- Ukraine aims to 'align' with US on minerals deal in talks this week - Reuters - April 8th, 2025 [April 8th, 2025]
- Ukraine to increase drone, robotics production, Zelensky says. - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- Ukraine war live: Zelensky confirms troops active in Russias Belgorod for first time - The Independent - April 8th, 2025 [April 8th, 2025]
- Zaluzhnyi reveals details of Wiesbaden HQ in Ukraine's war effort, calls it 'secret weapon'. - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- Warren Buffetts son is on track to donate $1 billion in aid to Ukraine this year - Fortune - April 8th, 2025 [April 8th, 2025]
- Citing war in Ukraine, dozens of groups call on NHL to reject hockey matchups with Russian league - NBC News - April 8th, 2025 [April 8th, 2025]
- Ukraine is undefeatable - The Telegraph - April 8th, 2025 [April 8th, 2025]
- Ukraine updates: Kyiv wants to 'align' with US over minerals - DW - April 8th, 2025 [April 8th, 2025]
- Monday, April 7. Russias War On Ukraine: News And Information From Ukraine - Forbes - April 8th, 2025 [April 8th, 2025]
- Ukraine-Russia war: Thousands of Wiltshire gas masks being sent to troops - BBC - April 8th, 2025 [April 8th, 2025]
- Ukraine-Russia war live: US to host Kyiv team for crucial minerals deal talks - The Independent - April 8th, 2025 [April 8th, 2025]
- 'I dont like the bombing' Trump responds to Russia-Ukraine peace talks question - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- More than 20 new fibre-optic drones appeared in Ukraine in 2025 Zelenskyy - Euromaidan Press - April 8th, 2025 [April 8th, 2025]
- Ukraine's Armed Forces have new combat robotic system with large-calibre machine gun photo - - April 8th, 2025 [April 8th, 2025]
- Russia's war casualty toll in Ukraine climbs by 1,290 in past day - Ukrinform - April 8th, 2025 [April 8th, 2025]
- 'Don't like them bombing on and on': Trump responds to question on Russia-Ukraine peace talks - Times of India - April 8th, 2025 [April 8th, 2025]
- Russian missile strike kills one, injures three in Kyiv, Ukraine says - Reuters - April 8th, 2025 [April 8th, 2025]
- Russia has found yet another excuse not to agree to a ceasefire in Ukraine, and it's not even a new one - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- Russian forces push to secure ground west of Oskil River in Kupiansk sector, Ukraine says - The Kyiv Independent - April 8th, 2025 [April 8th, 2025]
- Zelenskyy confirms for first time Ukraine forces active in Russia's Belgorod region - Sky News - April 8th, 2025 [April 8th, 2025]
- Putin suggests Ukraine could have UN-led government to organise elections - The Guardian - March 28th, 2025 [March 28th, 2025]
- UK and France to send defence chiefs to Ukraine as Starmer says Putin is 'playing for time' - BBC.com - March 28th, 2025 [March 28th, 2025]
- Russian medical researcher at Harvard, who protested the Ukraine war, detained by ICE - NBC News - March 28th, 2025 [March 28th, 2025]
- Things to know about the limited ceasefire between Russia and Ukraine brokered by the US - The Associated Press - March 28th, 2025 [March 28th, 2025]
- Trump reverses termination of program tracking mass child abductions in Ukraine - The Washington Post - March 28th, 2025 [March 28th, 2025]
- Trump administration rejects Putin's proposal that the U.N. should govern Ukraine - NBC News - March 28th, 2025 [March 28th, 2025]
- Putin floats idea of temporary government for Ukraine and talks tough about battlefield gains - CBS News - March 28th, 2025 [March 28th, 2025]
- Putin suggests temporary administration for Ukraine, Russian news agencies report - Reuters - March 28th, 2025 [March 28th, 2025]
- Illustrator George Butler: For Ukraine this is a record of the first draft of history. - CNN - March 28th, 2025 [March 28th, 2025]
- Putin Proposes Temporary Administration Running Ukraine And Trumps Greenland Ambitions - Forbes - March 28th, 2025 [March 28th, 2025]
- Ukraine and Russia do the Trump dance to shift blame for peace-talk problems - POLITICO Europe - March 28th, 2025 [March 28th, 2025]
- France and Britain mull plans to deploy troops to assist with Ukraine-Russia peace deal - PBS NewsHour - March 28th, 2025 [March 28th, 2025]
- Revealed: Trumps plan to force Ukraine to restore Putins gas empire - The Telegraph - March 28th, 2025 [March 28th, 2025]
- US pushes for more expansive minerals deal with Ukraine - Sky News - March 28th, 2025 [March 28th, 2025]
- Ukraine war latest: Putin uses nuclear submarine visit to call for elections in Ukraine under temporary government - as US responds - Sky News - March 28th, 2025 [March 28th, 2025]
- Amid truce talks, why is Ukraine focused on attacking western Russia? - Al Jazeera English - March 28th, 2025 [March 28th, 2025]
- Europeans Vow to Stand by Ukraine, but Disagree Over Force Proposal - The New York Times - March 28th, 2025 [March 28th, 2025]
- Europes talks on Ukraine security shift from sending troops - Reuters - March 28th, 2025 [March 28th, 2025]
- Ukraine and Russia Exchange Nearly 1K Bodies of Fallen Soldiers - The Moscow Times - March 28th, 2025 [March 28th, 2025]
- A Cuban Dancer on Escaping Ukraine and How to Survive War - Havana Times - March 28th, 2025 [March 28th, 2025]
- Ukraine and Russia Agree to Cease Fighting in the Black Sea, White House Says - The New York Times - March 28th, 2025 [March 28th, 2025]
- Trump teams rush to get Ukraine peace deal risks letting Russia off the hook for war crimes - POLITICO Europe - March 28th, 2025 [March 28th, 2025]
- Ukraine war latest: Putin accused of hollow peace claims as 74 wounded in Sumy - The Independent - March 25th, 2025 [March 25th, 2025]
- Europes War in Ukraine: The Continents Risky Task of Keeping Kyiv in the Fightand Defending Itself - Foreign Affairs Magazine - March 25th, 2025 [March 25th, 2025]
- Exclusive: Zelensky on Trump, Putin, and the Endgame in Ukraine - TIME - March 25th, 2025 [March 25th, 2025]
- Ukraine war: What are the issues in US talks with Ukraine and Russia? - Reuters - March 25th, 2025 [March 25th, 2025]
- Trump envoy Witkoff sparks outcry after backing Kremlin talking points on Ukraine - ABC News - March 25th, 2025 [March 25th, 2025]
- Russia and Ukraine Hold U.S.-Mediated Talks in Riyadh: What to Know - The New York Times - March 25th, 2025 [March 25th, 2025]
- I was defending the dignity of Ukraine: Zelenskyy addresses bust-up with Trump and Vance - POLITICO Europe - March 25th, 2025 [March 25th, 2025]