216.73.216.6

Campaigns Impersonate the CIA to Target Ukraine Sympathizers, Russian Citizens and Informants

· Published 01/04/2025 14:48 · Modified 02/04/2025 08:58

Export JSON

Essential information

Published
01/04/2025 14:48
Modified
02/04/2025 08:58
Tags
2025-04-01 cia hochuzhit impersonation intelligence gathering legion liberty phishing russia russian volunteer corps state-sponsored ukraine
Related entities
1 intrusion sets (apt), 6 techniques (mitre), 4 others

Description

Silent Push Threat Analysts have uncovered a sophisticated campaign targeting individuals sympathetic to 's defense, Russian citizens, and potential informants. The operation, believed to be orchestrated by Russian Intelligence Services, employs four major clusters impersonating the , , , and . These campaigns aim to collect personal information from victims through fake websites and forms. The threat actors utilize bulletproof hosting, domain spoofing, and Google Forms to lure targets into providing sensitive data. The campaign's persistence, long-term targeting of specific groups, and of official organizations without apparent financial motives strongly suggest involvement. Mitigation efforts include identifying and blocking associated domains and IPs.

External references