UAC-0099 Refines MATCHBOIL Malware With Cloudflare-Hidden Servers to Hit Ukrainian Organizations
ESET researchers have detailed how the UAC-0099 threat group has evolved its MATCHBOIL downloader with Cloudflare-concealed command servers, stronger code obfuscation, and anti-analysis checks. Victims span transportation, manufacturing,...
Nine-Day Scanning Surge Targets Unpatched Hikvision Cameras Across Ukraine
GreyNoise logged a sharp nine-day spike in scanning and exploitation attempts against internet-exposed Hikvision cameras in Ukraine, almost all aimed at the four-year-old, maximum-severity CVE-2021-36260 command injection flaw....
Konni-Linked Espionage Campaign Uses Fake PDFs to Target Ukraine-Focused Groups
A campaign dubbed Operation Conflict Compass uses PDF-themed Windows shortcuts and a downloader called VelvetCake against people working on Ukraine-related issues. Researchers link the operation to the North...
Russia’s Turla APT Deploys STOCKSTAY Backdoor Against Ukrainian Government and Military Targets
Russia-linked Turla (FSB Center 16) has been running a long-running espionage campaign deploying a new .NET backdoor called STOCKSTAY against Ukrainian government and military organizations since December 2022....
GREYVIBE: Russian-Aligned Hackers Use ChatGPT and Google Gemini to Build Cyberweapons Targeting Ukraine
A newly tracked threat actor called GREYVIBE is using generative AI tools including ChatGPT and Google Gemini to develop malware, generate phishing lures, and attack Ukrainian government, military,...
Ukrainian Intelligence Report: Russian APT Groups Intensify Cyber Operations — 5,927 Incidents, 37% Rise in 2025
A new intelligence report from Ukraine's National Security and Defense Council reveals Russian state-sponsored threat groups dramatically escalated cyber operations in 2025, with CERT-UA recording 5,927 incidents —...
APT28 Deploys New PRISMEX Malware Suite Against Ukraine and NATO in Sophisticated Espionage Campaign
Russia's APT28 (Fancy Bear) has launched a new campaign deploying the previously undocumented PRISMEX malware framework, which uses steganography, COM hijacking, and legitimate cloud services for C2. Targets...
CERT-UA Exposes APT Malware Campaign Targeting Eastern European Governments and Municipal Hospitals
Ukraine's CERT-UA has disclosed a sophisticated infostealer campaign targeting government bodies and municipal healthcare institutions across Eastern Europe. The malware harvests credentials from Chromium browsers and exfiltrates WhatsApp...