216.73.216.6

Targets Ukraine's Defense Forces using SPECTR malware alongside legitimate SyncThing

· Published 07/06/2024 08:33 · Modified 07/06/2024 09:09

Export JSON

Essential information

Published
07/06/2024 08:33
Modified
07/06/2024 09:09
Tags
2024-06-07 defense exfiltration spectr syncthing ukraine
Related entities
33 observables, 1 intrusion sets (apt), 19 techniques (mitre), 1 malware, 3 others

Description

The report describes a cyber attack campaign by the UAC-0020 (Vermin) threat group targeting 's Forces. The attackers utilized the malware in tandem with the legitimate software to exfiltrate sensitive data. The malicious payload was delivered via a password-protected archive containing a decoy PDF and an installer that deployed both 's legitimate components and 's malicious modules. 's capabilities included screen capture, file theft, password , and the ability to steal data from messaging apps and browsers. The stolen data was covertly synced to the attackers' infrastructure by leveraging 's P2P functionality.

External references