Key Ukrainian government and military targets hit by a malware attack in Ukraine

Year

2018

Month

November

Reference number

20181101

Impact area

Shore

Incident location

Incident country

Ukraine

Victim country

Ukraine

Victim identity

Key Ukrainian government and military targets

Victim Type

Other Government

Method

Malware

Attacker country

Russia

Summary:

In November 2018, key Ukrainian government and military targets got hit by a malware attack in Ukraine. The malware entered through a Backdoor entry called Pterodo. This Backdoor arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites. The latest version activates only on Windo+X105:AA105ws systems with language localization for Ukrainian, Belarusian, Russian, Armenian, Azerbaijani, Uzbek, Tatar, and other languages associated with former Soviet states; this makes it more difficult to perform automated analysis of the malware with certain tools. According to the CERT-UA bulletin, the new version of Pterodo generates a unique URL for command and control based on the serial number of the hard drive of the infected system. Data about the infected system is uploaded to that URL, allowing the attackers to analyse which tools to remotely install and run. The domains associated with the attack so far include updates-spreadwork.pw, dataoffice.zapto.org, and bitsadmin.ddns.net. Behind this attack was the Russian Gameradon Group which is tied to the Russian FSB. The attack is a Spyware war and disinformation campaign. The attacks were aimed at gathering intelligence that could be used for the ships. Due to this attack Russia seized Ukrainian vessels and imprisoned Ukrainian sailors. The attackers gained information that would have been very relevant in planning.

Reference URL

https://www.nextgov.com/cybersecurity/2018/12/russia-launched-cyber-attacks-against-ukraine-ship-seizures-firm-says/153387/
https://arstechnica.com/information-technology/2018/11/ukraine-detects-new-pterado-backdoor-malware-warns-of-russian-cyberattack/
https://intelnews.org/2018/12/12/01-2455/
https://www.trendmicro.com/vinfo/us/threat-encyclopedia/malware/backdoor.win32.pterodo.a
https://www.defenseone.com/technology/2018/12/russia-launched-cyber-attacks-against-ukraine-ship-seizures-firm-says/153375/