Cyber Security News

Ukraine Warns of Massive Cyberattack Targeting Telecommunications Operators

The Computer Emergency Response Team of Ukraine (CERT-UA) warns of massive cyberattacks targeting telecommunication operators.  According to the report, CERT-UA received information from a participant in the information exchange on the mass mailing of e-mails among media organizations of Ukraine including radio stations, newspapers, news agencies, etc titled “LIST of links to interactive maps”.

CrescentImp Malware

CERT-UA team says more than 500 destination email addresses have been identified. These emails contain an attached document. Upon opening the attachment, may begin downloading of CrescentImp malware.

Experts warn that cybercriminals have been increasingly resorting to email spamming from compromised addresses of public institutions.

A report says the attackers continue to exploit vulnerability tracked as (CVE-2022-30190) and are increasingly using e-mails from compromised government e-mail addresses.

A remote code execution vulnerability in Microsoft Windows Support Diagnostic Tool (MSDT) is currently tracked as CVE-2022-30190. The security issue can be triggered by either opening or selecting a specially crafted document and threat actors have been exploiting it in attacks since at least April 2022.

Infection chain dropping CrescentImp malware

Therefore, this activity is tracked by UAC-0113, attributed to the Sandworm group with a medium certainty level.  Notably, this group was involved in coordinating a massive attack on the energy sector of Ukraine in April.

Sandworm is a Russian threat actor associated (in MITRE’s ATT&CK catalogue) with Russia’s GRU military intelligence service and possibly best known for its role in the 2015 and 2016 cyberattacks against sections of Ukraine’s power grid.  This group has also been fingered for the 2017 NotPetya pseudo-ransomware attack and 2018’s Olympic Destroyer incident.

CERT-UA has given a set of indicators of compromise to help defenders identify CrescentImp infections. Nevertheless, it is unclear what type of malware family CrescentImp belongs to or its functionality. The hashes from CERT-UA show no detection at the moment on the Virus Total scanning platform.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity updates.

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

3 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

4 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

6 hours ago