Security News

Ukraine dismantles 5 disinformation bot farms, seizes 10,000 SIM cards
2022-03-28 20:23

The Ukrainian Security Service has announced that since the start of the war with Russia, it has discovered and shut down five bot farms with over 100,000 fake social media accounts spreading fake news. The network, which operated in Kharkiv, Cherkasy, Ternopil, and Zakarpattia, aimed to discourage Ukrainian citizens and instill panic by distributing false information about the Russian invasion and the status of the defenders.

Cybercriminals focusing on crypto donations to Ukraine to trick victims
2022-03-28 06:03

As the war in Ukraine unfolded, one way of helping was to donate cryptocurrency which resulted in over $50 million in crypto donations. Cybercriminals were quick to move and take advantage of this lucrative situation and inattentive victims.

Another Chinese Hacking Group Spotted Targeting Ukraine Amid Russia Invasion
2022-03-26 00:14

A Chinese-speaking threat actor called Scarab has been linked to a custom backdoor dubbed HeaderTip as part of a campaign targeting Ukraine since Russia embarked on an invasion last month, making it the second China-based hacking group after Mustang Panda to capitalize on the conflict. "The malicious activity represents one of the first public examples of a Chinese threat actor targeting Ukraine since the invasion began," SentinelOne researcher Tom Hegel said in a report published this week.

Racoon Stealer malware suspends operations due to war in Ukraine
2022-03-25 18:22

The cybercrime group behind the development of the Racoon Stealer password-stealing malware has suspended its operation after claiming that one of its developers died in the invasion of Ukraine. Racoon Stealer is an information-stealing trojan distributed under the MaaS model for $75/week or $200/month.

Distributor dumps Kaspersky to show solidarity with Ukraine
2022-03-25 04:04

Australian technology distributor Dicker Data has decided to end its commercial relationship with Russian security software vendor Kaspersky. Kaspersky confirmed that Dicker Data has chosen to end its relationship, and thanked the distributor for "Hard work, dedication and support" since taking on the account in 2019.

Russia bans Google News for "unreliable" info on war in Ukraine
2022-03-23 20:55

Roskomnadzor, Russia's telecommunications regulator, has banned Alphabet's news aggregator service Google News and blocked access to the news. Google.com domain for providing access to "Unreliable information" on the ongoing war in Ukraine.

Google: Chinese state hackers target Ukraine’s government
2022-03-18 13:58

Google's Threat Analysis Group says the Chinese People's Liberation Army and other Chinese intelligence agencies are trying to get more info on the ongoing Russian war in Ukraine. Google TAG Security Engineer Billy Leonard says Google notified Ukrainian government organizations targeted by a Chinese-sponsored hacking group.

Russia gets triggered by Ukraine joining NATO cyberdefense hub
2022-03-17 21:53

Russia's ambassador to Estonia today compared Ukraine's participation in NATO's Cooperative Cyber Defence Centre of Excellence intel-sharing cyberdefense hub to an attempt at blackmail. Although being accepted as a contributing participant, this does not make Ukraine a NATO member, but it will most likely tighten collaboration and will also allow it to gain access to NATO members' cyber-expertise and share its own.

Popular NPM Package Updated to Wipe Russia, Belarus Systems to Protest Ukraine Invasion
2022-03-17 21:36

In what's yet another act of sabotage, the developer behind the popular "Node-ipc" NPM package shipped a new version to protest Russia's invasion of Ukraine, raising concerns about security in the open-source and the software supply chain. Affecting versions 10.1.1 and 10.1.2 of the library, the changes introduced undesirable behavior by its maintainer RIAEvangelist, targeting users with IP addresses located either in Russia or Belarus, and wiping arbitrary file contents and replacing it with a heart emoji.

BIG sabotage: Famous npm package deletes files to protest Ukraine war
2022-03-17 09:51

This month, the developer behind the popular npm package 'node-ipc' released sabotaged versions of the library in protest of the ongoing Russo-Ukrainian War. Newer versions of the 'node-ipc' package began deleting all data and overwriting all files on developer's machines, in addition to creating new text files with "Peace" messages.