Russia’s digital warriors adapt to support the war effort in Ukraine … – CyberScoop
Russian and pro-Russian operatives continue to modify their hacking and influence operations aimed at Ukraine to extract intelligence and sway public opinion in favor of the war, Google researchers said in a report released Wednesday. The latest tactics include promoting highly produced YouTube videos as well as more traditional phishing campaigns.
Roughly 14 months after the Russian invasion of Ukraine, the cyber components of the Russian onslaught continues with nearly 60% of Russian-backed phishing campaigns targeting Ukraine, Billy Leonard, a security engineer with the Google Threat Analysis Group, wrote in an update on the most notable hacking campaigns the company observed between January and March of 2023.
The latest report includes new information operations from Russias elite hacking units as well as work from a group believed to be Belarusian, a staunch Russian ally. From traditional credential and intelligence gathering efforts to information operations aimed abroad and at Russian audiences to glorify war efforts, the ongoing cyber operations remain active and show signs of adaptations and new techniques, Leonard wrote.
One of Russias most prolific and elite hacking groups known widely as Sandworm, but tracked by Google as FROZENBARENTS continues to focus heavily on the war in Ukraine with campaigns spanning intelligence collection, IO, and leaking hacked data through Telegram, Leonard wrote. Believed to operate out of Russian Armed Forces Main Directorate of the General Staff, or GRU, Unit 74455, the group known best for its multiple successful Ukrainian power grid attacks and the NotPetya malware that racked up more than $10 billion in global damages maintains its perch atop the Russian-backed offensive hacking ecosystem.
FROZENBARENTS remains the most versatile GRU cyber actor with offensive capabilities including credential phishing, mobile activity, malware, external exploitation of services, and beyond, Leonard wrote. They target sectors of interest for Russian intelligence collection including government, defense, energy, transportation/logistics, education, and humanitarian organizations.
The group continues to exploit EXIM mail servers around the world, Leonard wrote, a tactic it has employed since 2019, according to a 2020 NSA advisory. Once compromised, the hosts have been observed accessing victim networks, interacting with victim accounts, sending malicious emails, and engaged in information operations (IO) activity.
FROZENBARENTS has also continued to target organizations associated with the Caspian Pipeline Consortium (CPC), one of the largest oil pipelines in the world that transports crude oil from Kazakhstan across Russian territory to the Black Sea, Leonard wrote. The group has targeted a range of unnamed Eastern European energy sector organizations using fake Windows update packages on a domain spoofing CPC that, if executed, loaded a variation of the Rhadamanthys malware that could then exfiltrate stored credentials, including browser cookies.
Dating back to December 2022, the group has also launced multiple waves of credential theft campaigns targeting Ukrainian defense industry, military and Ukr.net mail users, Leonard wrote.
The group has also been active in the information operation space, he said, creating online personas to push pro-Russian news and narratives and leak stolen data, Leonard wrote, such as the persona CyberArmyofRussia, or CyberArmyofRussia_Reborn.
Both the YouTube channel for CyberArmyofRussia, or CyberArmyofRussia_Reborn which was pulled down upon notification and the Instagram account had minimal engagement and a negligible number of subscribers or followers, Leonard wrote. The groups Telegram channel, launched April 1, 2022, remains robust, with frequent posts for nearly 23,000 subscribers. Google researchers assess that the channel was created and controlled by the elite hacking unit.
In several recent incidents, FROZENBARENTS compromised a webserver of the target organization and uploaded a webshell to maintain persistent access to the compromised system, Leonard wrote. The attackers then deployed Adminer, a single file PHP script for managing databases, to exfiltrate data of interest. Shortly after exfiltration, the data appeared on the CyberArmyofRussia_Reborn Telegram channel.
In another information operation, the Internet Research Agency notorious for its efforts to shape domestic U.S. opinion ahead of the 2016 presidential elections produced a series of YouTube Shorts, short-form videos akin to TikTok or Instagrams Reels. The group has focused particularly on narratives supportive of Russia and the business interests of Russian oligarch Yevgeny Prigozhin, especially the Wagner Group, Leonard wrote.
The U.S. Department of Justice indicted Prigozhin, a longtime associate of Russian President Vladimir Putin, in 2018 for his role in the IRA interference operation. He is currently wanted by the FBI.
The group was also promoting a new film by Aurum LLC, a film company partially owned by Prigozhin. This movie has a high production value and communicates narratives portraying the Wagner Group in a positive light, Leonard wrote.
Altogether, Moscow continues to leverage the full spectrum of information operationsfrom overt state-backed media to covert platforms and accountsto shape public perception of the war in Ukraine, Leonard wrote.
Smaller campaigns from other hacking groups caught Googles eye as well.
Another operation attributed to the GRU as well but perhaps a unit other than FROZENBARENTS has since April 2022 maintained a Telegram channel to promote and amplify narratives related to the use of biological weapons in Ukraine and how the United States is responsible for the proliferation of biological weapons around the world, Leonard wrote. This campaign involves a Russian-language Telegram channel and an English Substack newsletter, which has published only once.
APT28 known widely as Fancy Bear, and tracked as FROZENLAKE sent multiple large waves of phishing emails to hundreds of users in Ukraine in February and March, Leonard wrote. Part of the effort involved reflected cross-site scripting (XSS) on multiple Ukrainian websites, which represents a new tactic for the group.
A Belarusian-linked hacking campaign tracked as PUSCHA by Google but sometimes called UNC1151 andlinked to Belarus by Mandiantin November 2021 has consistently targeted users in Ukraine and neighboring countries throughout the war, Leonard wrote, typically targeting the i.ua and meta.ua webmail services. Leonard described the phishing campaigns as targeted, and focused on small numbers of users in Ukraine.
Written by AJ VicensAJ covers nation-state threats and cybercrime. He was previously a reporter at Mother Jones. Get in touch via Signal/WhatsApp: (810-206-9411).
View post:
Russia's digital warriors adapt to support the war effort in Ukraine ... - CyberScoop
- Trump-Orbn meet: Russian oil imports and war in Ukraine to feature - Euronews.com - November 7th, 2025 [November 7th, 2025]
- Russian Forces in Ukraine Near First Major Conquest in More Than Two Years - WSJ - The Wall Street Journal - November 7th, 2025 [November 7th, 2025]
- Ukraine claims to have hit major Russian oil refinery with drones - The Independent - November 7th, 2025 [November 7th, 2025]
- EU tightens visa restrictions on Russians over the Ukraine war and acts of sabotage - abcnews.go.com - November 7th, 2025 [November 7th, 2025]
- EU set to further tighten controls for Russians amid ongoing Ukraine aggression - France 24 - November 7th, 2025 [November 7th, 2025]
- Angelina Jolies Driver in Ukraine Is Taken Away for the Draft - The New York Times - November 7th, 2025 [November 7th, 2025]
- Angelina Jolies unannounced visit to Ukraine includes unexpected drama - politico.eu - November 7th, 2025 [November 7th, 2025]
- Ukrainian border guards thank Angelina Jolie for supporting Ukraine and present her with gift photos - - November 7th, 2025 [November 7th, 2025]
- Ukraine's army fights to hold Pokrovsk in a battle for territory and narratives - abcnews.go.com - November 7th, 2025 [November 7th, 2025]
- Ukraine stepping up assaults on Russian forces in Dobropillia to ease pressure on Pokrovsk, general says - Reuters - November 7th, 2025 [November 7th, 2025]
- This Week in the Russia-Ukraine War (November 7) - Defense Security Monitor - November 7th, 2025 [November 7th, 2025]
- How Ukraine is losing the Donbas - The Parliament Magazine - November 7th, 2025 [November 7th, 2025]
- Ukraine says more than 1,400 Africans from dozens of countries fighting for Russia - Reuters - November 7th, 2025 [November 7th, 2025]
- Why the fall of Pokrovsk would matter to Ukraine and Russia - BBC - November 7th, 2025 [November 7th, 2025]
- Ukraine Digs In to Try to Halt Biggest Russian Win in Two Years - Bloomberg.com - November 7th, 2025 [November 7th, 2025]
- Ukraine soldiers now earn points for confirmed kills, prompting fears of a gamified war - CBC - November 7th, 2025 [November 7th, 2025]
- Fears Pokrovsk will fall within weeks as Ukraine sends in its elite units - The Independent - November 7th, 2025 [November 7th, 2025]
- Ukraine faces forever war unless Europe steps up pressure on Russia, says ex-Nato chief - The Guardian - November 7th, 2025 [November 7th, 2025]
- Guns and Ammo: The Ukraine War and NATOs Ammunition Interoperability Problem - Modern War Institute - - November 7th, 2025 [November 7th, 2025]
- Trump talks Ukraine war, sanctions with Hungary's Orbn - Spectrum News - November 7th, 2025 [November 7th, 2025]
- Putins archrival warns Europe: Brace for Cold War II whatever happens in Ukraine - politico.eu - November 7th, 2025 [November 7th, 2025]
- Ukraine estimates its long-range weapon production at over $30 billion in 2026 - The Kyiv Independent - November 7th, 2025 [November 7th, 2025]
- As attacks on infrastructure intensify, Ukraine faces a looming winter crisis - ReliefWeb - November 7th, 2025 [November 7th, 2025]
- Women in Ukraine's army fight Russia and sexism - DW - November 7th, 2025 [November 7th, 2025]
- Trump and Orbn Discuss Russian Oil, Sanctions, and Ukraine at White House Meeting - UNITED24 Media - November 7th, 2025 [November 7th, 2025]
- The President of Ukraine and the President of Lebanon Discussed Bilateral Cooperation and Agreed on Further Work of Their Teams - - - November 7th, 2025 [November 7th, 2025]
- Orban meets Trump in Washington to discuss Russian oil, war against Ukraine - The Kyiv Independent - November 7th, 2025 [November 7th, 2025]
- Ukraine to Boost Ground Drone Fleet With 30,000 Units in 2026: Report - The Defense Post - November 7th, 2025 [November 7th, 2025]
- Ukraine in Positive Talks to Buy US Tomahawks, Even as Trump Says No Ambassador - Kyiv Post - November 7th, 2025 [November 7th, 2025]
- Angelina Jolie Visits Ukraine for the Second Time Since the Start of the War - Vanity Fair - November 7th, 2025 [November 7th, 2025]
- Video captures aftermath of attack on town near Ukraine front line - BBC - November 5th, 2025 [November 5th, 2025]
- Video captures aftermath of attack on town near Ukraine front line - BBC - November 5th, 2025 [November 5th, 2025]
- Ukraine war latest: Putin makes fresh nuclear test demand after Trump threat - The Independent - November 5th, 2025 [November 5th, 2025]
- Zelenskyy calls for Ukraine to join EU before 2030 after commission delivers warning on corruption - as it happened - The Guardian - November 5th, 2025 [November 5th, 2025]
- Russia and Ukraine says their forces are locked in fierce fighting in the ruins of Pokrovsk - Reuters - November 5th, 2025 [November 5th, 2025]
- Ukraine to rename the kopeck coin in another break with Russia - Reuters - November 5th, 2025 [November 5th, 2025]
- EU Assistance Mission Ukraine building sustainable capacities in war-affected areas - EEAS - November 5th, 2025 [November 5th, 2025]
- Why talk of the fall of Pokrovsk and Ukraine is premature - The Independent - November 5th, 2025 [November 5th, 2025]
- Ukraine to rename the kopeck coin in another break with Russia - Reuters - November 5th, 2025 [November 5th, 2025]
- Ukraine war briefing: Kyiv gets more US-made Patriots and says its forces are holding on in Pokrovsk - The Guardian - November 5th, 2025 [November 5th, 2025]
- Drones Wont Save Us: Learning the Wrong Lessons from Ukraine Will Cost the US Army its Edge in Maneuver Warfare - Modern War Institute - - November 5th, 2025 [November 5th, 2025]
- Nineteen Uzbek Citizens Repatriated from Ukraine After Forced Labor Exploitation - The Times Of Central Asia - November 5th, 2025 [November 5th, 2025]
- Ukraine war briefing: Kyiv gets more US-made Patriots and says its forces are holding on in Pokrovsk - The Guardian - November 5th, 2025 [November 5th, 2025]
- Norway to allocate $7 billion in aid to Ukraine in 2026 - The Kyiv Independent - November 5th, 2025 [November 5th, 2025]
- Norway to allocate $7 billion in aid to Ukraine in 2026 - The Kyiv Independent - November 5th, 2025 [November 5th, 2025]
- Mobile Medical Clinics Expand Health Care Access in Ukraine - Angels in Medicine - November 5th, 2025 [November 5th, 2025]
- Russia and Ukraine Says Their Forces Are Locked in Fierce Fighting in the Ruins of Pokrovsk - U.S. News & World Report - November 5th, 2025 [November 5th, 2025]
- Russia and Ukraine Says Their Forces Are Locked in Fierce Fighting in the Ruins of Pokrovsk - U.S. News & World Report - November 5th, 2025 [November 5th, 2025]
- Ukraine: Coordinated action secures salary increase for teachers - Education International - November 5th, 2025 [November 5th, 2025]
- Joint Expeditionary Force launches enhanced partnership with Ukraine as allies step up further - GOV.UK - November 5th, 2025 [November 5th, 2025]
- Volodymyr Zelenskyy and Gitanas Nausda Discussed Energy Support for Ukraine - - - November 5th, 2025 [November 5th, 2025]
- Russia Uses Fake Journalist Invitations to Spread Propaganda on Ukraine Fronts - UNITED24 Media - November 5th, 2025 [November 5th, 2025]
- Ukraine and Russia locked in intense clash over key strategic city of Pokrovsk - Australian Broadcasting Corporation - November 5th, 2025 [November 5th, 2025]
- Russia Uses Fake Journalist Invitations to Spread Propaganda on Ukraine Fronts - UNITED24 Media - November 5th, 2025 [November 5th, 2025]
- Families of Indians trapped in Russias war in Ukraine cry for help - TVP World - November 5th, 2025 [November 5th, 2025]
- Kremlin: Ukraine is concealing dire situation of its forces in east - Yahoo - November 5th, 2025 [November 5th, 2025]
- Chart of the week: What do Ukraine's front-line communities need? - The Kyiv Independent - November 5th, 2025 [November 5th, 2025]
- Man Claiming to Have Cut Off Heads in Ukraine Arrested After Knife Threat in Minsk Caf - UNITED24 Media - November 5th, 2025 [November 5th, 2025]
- Ukraine war is in a "stalemate" due to slow European aid and US reluctance - France 24 - November 5th, 2025 [November 5th, 2025]
- Democrats Win Big How Does That Affect Ukraine? - Kyiv Post - November 5th, 2025 [November 5th, 2025]
- Record fruit and berry prices in Ukraine amid weather challenges - FreshPlaza - November 5th, 2025 [November 5th, 2025]
- Pokrovsk: Fighting intensifies around key town in Ukraine amid fresh attacks on Russian energy - CNN - November 3rd, 2025 [November 3rd, 2025]
- These people just escaped Russian-occupied Ukraine but some say they need to go back - The Kyiv Independent - November 3rd, 2025 [November 3rd, 2025]
- U.S. family moved to Russia to escape liberal culture and got drawn into the war with Ukraine - NBC News - November 3rd, 2025 [November 3rd, 2025]
- Ukraine war briefing: Russian attacks on substations are nuclear terrorism, says Ukraine - The Guardian - November 3rd, 2025 [November 3rd, 2025]
- Ukraine live: Putin accused of nuclear terrorism as his forces mass around key town - The Independent - November 3rd, 2025 [November 3rd, 2025]
- Russias war casualty toll in Ukraine up by 1,160 over past day - Ukrinform - November 3rd, 2025 [November 3rd, 2025]
- Americas Magical Thinking on Ukraine and North Korea - The American Conservative - November 3rd, 2025 [November 3rd, 2025]
- There Is a Good Result for Our Air Defense Ukraine Now Has More Patriots Address by the President - - - November 3rd, 2025 [November 3rd, 2025]
- Ukraine's energy sector again target of overnight Russian strikes - Euronews.com - November 3rd, 2025 [November 3rd, 2025]
- What if there's no reparations loan for Ukraine? EU weighs options - Euronews.com - November 3rd, 2025 [November 3rd, 2025]
- Ukraine has hit nearly 160 Russian oil facilities in 2025, SBU says - The Kyiv Independent - November 3rd, 2025 [November 3rd, 2025]
- Trump says hes not sending Tomahawk missiles to Ukraine at this moment - Latest news from Azerbaijan - November 3rd, 2025 [November 3rd, 2025]
- Exclusive: Russia uses missile in Ukraine that led Trump to quit nuclear treaty, Kyiv says - Reuters - October 31st, 2025 [October 31st, 2025]
- Ukraine says it destroyed one of Russia's new Oreshnik ballistic missiles in a covert operation - Business Insider - October 31st, 2025 [October 31st, 2025]
- Ukraine war live: Kremlin demands collapsed Trump-Putin talks, report says - The Independent - October 31st, 2025 [October 31st, 2025]
- Russias Treaty-Busting Screwdriver Cruise Missile Used Against Ukraine: Officials - The War Zone - October 31st, 2025 [October 31st, 2025]
- Trump warned Ukraine war is creating significant risks for US economy in new report urging end to conflict - The Independent - October 31st, 2025 [October 31st, 2025]
- Ukraine war briefing: British ex-soldier arrested in Kyiv and accused of spying for Russia - The Guardian - October 31st, 2025 [October 31st, 2025]
- Ukraine: Russian attacks on energy could trigger major crisis within crisis - Department of Political and Peacebuilding Affairs - October 31st, 2025 [October 31st, 2025]