The emails appear as if having been sent by Ukraine’s SBU security service, making the victims more likely to trust their contents.
According to the report, the hackers' emails contain a link to download a file named "Documents.zip." If clicked, the link initiates the download of an MSI file. Opening this file triggers the launch of the ANONVNC malware, which allows attackers to gain unauthorized access to the victim's computer.
Ukraine’s Computer Emergency Response Team (CERT-UA) has detected over 100 computers infected with this malware, including among state and local government entities.
According to the message, urgent measures have been taken to reduce the likelihood of the malware spreading further.