Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Ukrainian Government Targeted with Fake Windows Update
News & Analysis Attacks Phishing Threats and Vulnerabilities

Ukrainian Government Targeted with Fake Windows Update

Olivia WilliamBy Olivia WilliamMay 1, 2023Updated:August 22, 20244 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Ukrainian Government Targeted with Fake Windows Update
Ukrainian Government Targeted with Fake Windows Update
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Various government entities in the nation have been the target of cyberattacks by Russian nation-state hackers, all based on the Computer Emergency Response Team of Ukraine (CERT-UA). APT28, also known as Fancy Bear, Forest Blizzard, FROZENLAKE, Iron Twilight, Sednit, and Sofacy, was blamed by the agency for the phishing effort.

The emails have “Windows Update” as their subject line and claim to offer instructions in Ukrainian for running a PowerShell operation under the guise of security updates. When the script is run, a subsequent PowerShell script is created to gather fundamental system information via tasks like tasklist and systeminfoand exfiltrate it using an HTTP request to the loaded and active Mocky API.

https://twitter.com/TheHackersNews/status/1652959568777945089

The emails used phony Microsoft Outlook email accounts made using the employees’ real names and initials to impersonate system administrators of the targeted government agencies in order to fool the targets into running the command.

CERT-UA advises enterprises to limit individuals’ access to PowerShell script execution and network connection monitoring for the Mocky API. The information was revealed a few weeks after APT28 was linked to assaults that made use of security holes in networking hardware that have since been patched to conduct reconnaissance and launch malware against a limited number of targets.

In a warning released last month, Google’s Threat Analysis Group (TAG) described a credential harvesting operation conducted by the threat actor to divert users of Ukrainian official websites to phishing domains.

The use of a major privilege escalation vulnerability in Microsoft Outlook (CVE-2023-23397, CVSS score: 9.8) in incursions targeting the European government, transportation, energy, and military sectors has also been connected to hacking groups located in Russia.

Additionally, the development coincides with the discovery by Fortinet FortiGuard Labs of a multi-stage phishing attack that uses a Word document laced with macros purportedly from Ukraine’s Energoatom as a lure to deliver the open-source Havoc post-exploitation framework.

According to a study released earlier this year by cybersecurity firm Recorded Future, it is still quite possible that Russian intelligence, military, and law enforcement agencies have a long-standing, implicit understanding with cybercriminal threat actors. In some circumstances, it is essentially known that these organizations have a formalized and organized link with cybercrime threat actors, either through covert collaboration or recruiting.

Conclusion

Russian hackers are sending malicious emails to Ukrainian government agencies with instructions on how to upgrade Windows to protect against cyberattacks. According to CERT-UA. APT28 (aka Fancy Bear), a Russian state-sponsored hacking outfit, sent these emails and impersonated government system administrators to fool their targets, according to CERT-UA. The attackers used genuine employee identities to generate @outlook.com email addresses. Malicious emails tell recipients to use a PowerShell command instead of upgrading Windows.

This command simulates a Windows update by downloading a PowerShell script and a second payload in the background. The second-stage payload is a simple data harvester that leverages the ‘tasklist’ and’systeminfo’ commands to transfer data to a Mocky service API through an HTTP request. CERT-UA advises system administrators to restrict PowerShell on important machines and monitor network traffic for Mocky service API interactions. Google’s Threat Analysis Group found that 60% of phishing emails targeting Ukraine in the first quarter of 2023 were from Russian threat actors, including APT28.

US and UK intelligence services and Cisco warned earlier this month that APT28 was actively exploiting a zero-day hole in Cisco routers to implant ‘Jaguar Tooth’ malware to collect intelligence from US and EU targets. APT28 has exploited an Outlook zero-day vulnerability, CVE-2023-23397, since April 2022 to attack European government, military, energy, and transportation networks. Microsoft patched it in March 2023. Last year, Chinese hackers lured Russian government entities with Windows updates to drop malicious executables.

Olivia William
  • Olivia William
    Ciso Playbook: Cyber Resilience Strategy
  • Olivia William
    Apple Responds Swiftly to Active Security Threats with iOS 16.5.1 Update
  • Olivia William
    Zacks Investment Research Faces Larger Data Breach Affecting 8.8 Million Users
  • Olivia William
    British Airways and Boots Battling Data Breaches, Millions of Customers Affected

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}