By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Home
  • News
  • Technology
  • Games
  • Review
Reading: Russian ‘WhisperGate’ hackers are using new data-stealing malware to target Ukraine
Share
Notification Show More
Latest News
Fairphone 2 gets its final software update, seven years after original release
March 7, 2023
Tensor raises $3M for Solana-focused NFT trading platform
March 7, 2023
Assured Allies secures $42.5M Series B to help Americans ‘successfully age’
March 7, 2023
ADHD startups are exploding, and now there even a dedicated browser
March 7, 2023
ADHD startups are exploding, and now there even a dedicated browser
March 7, 2023
Home
Search
  • News
  • Technology
  • Games
  • Review
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News /

Russian ‘WhisperGate’ hackers are using new data-stealing malware to target Ukraine

Published February 8, 2023
Last updated: 2023/02/08 at 3:03 AM
Share

Security researchers say they have recently observed a Russian hacking crew, who were behind the destructive WhisperGate malware cyberattacks, targeting Ukrainian entities with a new information-stealing malware.

Symantec’s Threat Hunter Team has attributed this campaign to a Russia-linked cyber threat actor, widely known as TA471 (or UAC-0056), which has been active since early 2021. The group is known to support Russian government interests, and while it primarily targets Ukraine, the group has also been active against NATO member states in North America and Europe. TA471 has been linked to WhisperGate, a destructive data-wiping malware that was used in multiple cyberattacks against Ukrainian targets in January 2022. The malware masquerades as ransomware, but renders targeted devices completely inoperable and unable to recover files even if a ransom demand is paid.

According to Symantec, the hacking crew’s latest campaign relies on previously unseen information-stealing malware it calls “Graphiron” for targeting Ukrainian organizations. The malware was used to steal data from infected machines from October 2022 until at least mid-January 2023, according to the researchers, reasonable to assume that it remains part of the [hackers’] toolkit.”

The info-stealing malware uses file names designed to masquerade as legitimate Microsoft Office files, and is similar to other TA471 tools, such as GraphSteel and GrimPlant, which were previously used as part of a spear-phishing campaign specifically targeting Ukrainian state bodies. But Symantec says that Graphiron is designed to exfiltrate far more data, including screenshots and private SSH keys.

“That information could be useful in itself from an intelligence perspective, or it could be used to penetrate deeper into the targeted organization or to launch destructive attacks,” Dick O’Brien, principal intelligence analyst Symantec Threat Hunter Team, told TechCrunch.

O’Brien said that while little is known about the hacking crew’s origin or strategy, TA471 has become one of the key players in Russia’s ongoing cyber campaigns against Ukraine.

News of TA471’s latest espionage campaign comes days after the Ukrainian government sounded the alarm on another Russian state-sponsored hacking group, dubbed UAC-0010, which continues to conduct frequent cyber attack campaigns against Ukrainian organizations.

“Despite using mainly repeated sets of techniques and procedures, adversaries slowly but insistently evolve in their tactics and redevelop used malware variants to stay undetected,” said Ukraine’s State Cyber Protection Centre. “Therefore, it remains one of the key cyber threats facing organizations in our country.”

US says destructive wiper malware targeting Ukraine could ‘spill over’ to other countries

Russian ‘WhisperGate’ hackers are using new data-stealing malware to target Ukraine by Carly Page originally published on TechCrunch

You Might Also Like

Fairphone 2 gets its final software update, seven years after original release

Tensor raises $3M for Solana-focused NFT trading platform

Assured Allies secures $42.5M Series B to help Americans ‘successfully age’

ADHD startups are exploding, and now there even a dedicated browser

ADHD startups are exploding, and now there even a dedicated browser

February 8, 2023
Share
Previous Article Chinese influence, loan-collection practices reasons for India’s crackdown on lending apps
Next Article Russian ‘WhisperGate’ hackers are using new data-stealing malware to target Ukraine
Keyboard Apps Suited for Android Devices
Technology
MGCOOL Explorer 2, built-in gyroscope to achieve image stabilization
Technology

© Giplay News Network. All Rights Reserved.

  • About
  • Advertise
  • Privacy Policy
  • Contact

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?