Security News > 2023 > October > Russian Sandworm hackers breached 11 Ukrainian telcos since May

Russian Sandworm hackers breached 11 Ukrainian telcos since May
2023-10-16 18:06

The agency states that the Russian hackers "Interfered" with the communication systems of 11 telcos in the country, leading to service interruptions and potential data breaches.

Sandworm is a very active espionage threat group linked to Russia's GRU. The attackers have focused on Ukraine throughout 2023, using phishing lures, Android malware, and data-wipers.

The attacks begin with Sandworm performing reconnaissance on telecommunication company's networks using the 'masscan' tool to perform scans on the target's network.

To make their intrusions stealthier, Sandworm uses 'Dante', 'socks5,' and other proxy servers to route their malicious activities through servers within the Ukrainian internet region they compromised previously, making it appear less suspicious.

Sandworm uses the 'Whitecat' tool to remove the attack's traces and delete access logs.

GRU hackers attack Ukrainian military with new Android malware.


News URL

https://www.bleepingcomputer.com/news/security/russian-sandworm-hackers-breached-11-ukrainian-telcos-since-may/