Skip to main content

Mass Credential Harvesting campaigns, targeting Ukrainian organizations

23.03.2023

The Cyber Incident Response Operations Center of the State Cyber Protection Centre of Ukraine fixates the increase in mass credential harvesting campaigns since the beginning of 2023.

All the detected emails as well as attached files are composed in Russian language, usually include impersonation of the targeted entities and manipulate the password expiring theme, luring the victims to update credentials as soon as possible in order to save account access.

These campaigns have been targeting Asia and Europe regions since August, 2021. The phishing emails attributed to the same activity cluster have been distributed to the Ukrainian corporate email addresses since May, 2022.

The high-level overview of the attack landscape, adversary infrastructure and attack chains of such credential harvesting campaigns are provided in the report.

The Cyber Incident Response Operations Center of the State Cyber Protection Centre of Ukraine underlines the importance of following basic cyber hygiene and cybersecurity guidelines as well as staying informed about the latest threats in order to be able to recognize and avoid phishing scams, especially in corporate environments.

Download pdf.



Image for the article

By topic «Security»

11.10.2024

The State Cyber Protection Center strengthens the nation's cyber resilience through cooperation with partners.

19.06.2024

The State Cyber Protection Centre of the State Service of Special Communications and Information Protection of Ukraine (SCPC SSSCIP) is increasing technical capabilities of the National Center for Reserving State Information Resources.

30.04.2024

The State Cyber Protection Center boosts technical capacities of the National Center for Public Information Resources Backup

18.04.2024

The State Cyber Protection Center boosts technical capacities of the National Center for Public Information Resources Backup

19.03.2024

The State Cyber Protection Center together with Palo Alto Networks Unit 42 have studied the SmokeLoader malware

More news