Russian hackers target Ukraine’s energy infrastructure in a new series of attacks

Russian hackers target Ukraine’s energy infrastructure in a new series of attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has shared technical details and Indicators of Compromise associated with a recently observed attack on the country’s energy infrastructure facility orchestrated by a Russian military hacking unit widely known as APT28, Fancy Bear or Strontium.

In this case, the attack involved a phishing email with a malicious link leading to a ZIP archive containing three JPG images (lures) and a BAT file called “weblinks.cmd.”

Upon execution, the batch file will open several web pages serving as bait, create two “.bat” and “.vbs” files, and run a VBS file.

An analysis revealed that the threat actor used the file.io tool to download the Tor software and set up a hidden service to route the data through the network to local hosts. The attackers also used a legitimate service called webhook.site for remote command execution, as well as LOLBAS (Living Off The Land Binaries And Scripts) techniques to bypass security solutions.

The Ukrainian cyber defenders said that the attack was thwarted by an employee of the targeted organization.

Earlier this year, APT28 attempted to hack government institutions and military entities involved in aircraft infrastructure in Ukraine via security flaws in vulnerable RoundCube webmail servers.


Back to the list

Latest Posts

Cyber Security Week in Review: April 18, 2025

Cyber Security Week in Review: April 18, 2025

In brief: Apple fixes a couple of iOS zero-days, a Windows NTLM bug exploited in real-world attacks, and more.
18 April 2025
Apple fixes two actively exploited iOS zero-days

Apple fixes two actively exploited iOS zero-days

The flaws have been used in “extremely sophisticated attacks” targeting specific individuals.
17 April 2025
New BPFDoor controller targeting telecoms sector in Asia and the Middle East

New BPFDoor controller targeting telecoms sector in Asia and the Middle East

The campaign is attributed to a well-known cyber espionage group known as Earth Bluecrow.
16 April 2025