/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Google finds Android spyware, distributed outside the Play Store, that Russians disguised as an app for Ukrainians to launch DDoS attacks against Russian sites

Details were published in a blog post from the Threat Analysis Group, which tracks state-backed cyber activity

The Verge Corin Faife

Discussion

  • @jsrailton John Scott-Railton on x
    NEW: 🇷🇺Russian FSB-backed group #Turla distributed app to people that wanted to help #Ukraine do cyberwar. It was actually android malware. Clever idea, but it doesn't sound like many users fell for it. @Google's blog by @billyleonard https://blog.google/... https://twitter.com/.…
  • @evacide Eva on x
    Surprise! An app that was advertised as a tool to help Ukrainians launch DDoS attacks against Russian sites was, in fact, malware designed to track and identify them. https://twitter.com/...
  • @petercorless @petercorless on x
    Amateurs should not be trying to crowdsource DDoS attacks using dodgy mobile apps. This isn't time for “SETI At Home meets The Matrix.” For the love of God, if you don't even know what a TCP/IP socket is, do not just download “hacker” tools. You're not Neo. https://twitter.com/..…
  • @instacyber @instacyber on x
    The CyberAzov activity is interesting but I believe there are some flaws in the reporting here. 1. One of the apps at least attempts to continue an attack, so the assertion of single GET requests doesn't appear to be correct (might change purpose hypothesis) 1/n https://twitter.c…
  • @ngleicher Nathaniel Gleicher on x
    Interesting find — makes perfect sense to hide an exploit behind this type of appeal. Never forget: social engineering is an essential element of almost every exploit. https://twitter.com/...
  • @shanehuntley Shane Huntley on x
    This was a strange one. It really feels we are finding more and more creative and strange campaigns from APT actors recently. Keeps things interesting. https://twitter.com/...