Google finds Android spyware, distributed outside the Play Store, that Russians disguised as an app for Ukrainians to launch DDoS attacks against Russian sites
Details were published in a blog post from the Threat Analysis Group, which tracks state-backed cyber activity
The Verge Corin Faife
Related Coverage
- Russian hackers use fake DDoS app to infect pro-Ukrainian activists BleepingComputer · Sergiu Gatlan
- Continued cyber activity in Eastern Europe observed by TAG The Keyword · Billy Leonard
- Russia Released a Ukrainian App for Hacking Russia That Was Actually Malware VICE · Lorenzo Franceschi-Bicchierai
- Russian hackers use fake pro-Ukraine Android apps to spread malware Silicon Republic · Vish Gain
- Russian Hackers Target Ukrainians Via Copycat DoS App Infosecurity · Phil Muncaster
- Russian Hackers Tricked Ukrainians with Fake “DoS Android Apps to Target Russia” The Hacker News · Ravie Lakshmanan
- Russia sought to unmask Ukrainian hackers with malware app, Google says The Hill · Julia Mueller
Discussion
-
@jsrailton
John Scott-Railton
on x
NEW: 🇷🇺Russian FSB-backed group #Turla distributed app to people that wanted to help #Ukraine do cyberwar. It was actually android malware. Clever idea, but it doesn't sound like many users fell for it. @Google's blog by @billyleonard https://blog.google/... https://twitter.com/.…
-
@evacide
Eva
on x
Surprise! An app that was advertised as a tool to help Ukrainians launch DDoS attacks against Russian sites was, in fact, malware designed to track and identify them. https://twitter.com/...
-
@petercorless
@petercorless
on x
Amateurs should not be trying to crowdsource DDoS attacks using dodgy mobile apps. This isn't time for “SETI At Home meets The Matrix.” For the love of God, if you don't even know what a TCP/IP socket is, do not just download “hacker” tools. You're not Neo. https://twitter.com/..…
-
@instacyber
@instacyber
on x
The CyberAzov activity is interesting but I believe there are some flaws in the reporting here. 1. One of the apps at least attempts to continue an attack, so the assertion of single GET requests doesn't appear to be correct (might change purpose hypothesis) 1/n https://twitter.c…
-
@ngleicher
Nathaniel Gleicher
on x
Interesting find — makes perfect sense to hide an exploit behind this type of appeal. Never forget: social engineering is an essential element of almost every exploit. https://twitter.com/...
-
@shanehuntley
Shane Huntley
on x
This was a strange one. It really feels we are finding more and more creative and strange campaigns from APT actors recently. Keeps things interesting. https://twitter.com/...