Hackers leverage popular encrypted app, disguising malware payloads as military recruitment offers
Nation9 January 2024, 01:09 PM
The government's Computer Emergency Response Team of Ukraine, CERT-UA, which operates under the State Special Communications Service, took measures against these cyberattacks, SSCS reported.
Suspicious activity was detected by experts of the American-Japanese company Trendmicro at the end of December 2023, which was relayed to CERT-UA, the Service said.
The hackers' messages contain archive files, the launch of which will infect the computer with REMCOSRAT and REVERSESSH malware.
The names and contents of the archives are specifically made to sound interesting for the military – "prisoner interrogation", "geolocations", "coding commands", "call signs", etc.