The latest report from Ukraine's computer emergency response team, CERT-UA, highlights a concerning trend of hackers targeting messaging apps used by Ukrainian soldiers. This surge is attributed to a group identified as UAC-0184. The agency warns soldiers to be cautious online, as their activities could make them vulnerable to physical attacks.
UAC-0184 employs various malware, including HijackLoader and Remcos, to gain access to systems. They also use tools like ViottoKeylogger, XWorm, Tusc, and Sigtop to extract data from apps like Signal. Hackers use tactics such as disguising malicious files as fake court documents or frontline videos to trick victims.
Despite previous considerations for a secure military app, most Ukrainian soldiers still rely on popular services like Telegram, Signal, Viber, and WhatsApp. This threat landscape underscores the ongoing vulnerability of military communication systems, particularly in conflict zones like Ukraine, where Russian-backed hackers have been actively targeting messaging apps to intercept sensitive information.
Takeaways:
Source and further reading.
Ukrainian soldiers’ apps increasingly targeted for spying, cyber agency warns. (n.d.).
https://therecord.media/ukraine-military-personnel-cyber-espionage-uac-0184
Cyware. (n.d.). UAC-0184 Targets Ukrainian Entity in Finland with Remcos RAT.
Cyware Labs.
https://cyware.com/news/uac-0184-targets-ukrainian-entity-in-finland-with-remcos-rat-6b6efe4f
CERT-UA. (n.d.). cert.gov.ua.
https://cert.gov.ua/article/6278521