{"id":5970,"date":"2024-10-28T15:22:45","date_gmt":"2024-10-28T20:22:45","guid":{"rendered":"https:\/\/www.darkreading.com\/threat-intelligence\/russia-kneecaps-ukraine-army-recruitment-spoofed-civil-defense-app"},"modified":"2024-10-28T15:22:45","modified_gmt":"2024-10-28T20:22:45","slug":"russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/10\/28\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app\/","title":{"rendered":"Russia Kneecaps Ukraine Army Recruitment With Spoofed &#8216;Civil Defense&#8217; App"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt625ecf02a4e18d4e\/671fe4b985012a9ac36a4f5b\/Ukraine_Army_Bumble_Dee_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ukrainian efforts to recruit new soldiers to serve in its military in the country&#8217;s war against Russia is under a two-pronged cyberattack by Kremlin-backed threat actors.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Researchers at Google&#8217;s Threat Intelligence Group (TAG) and Mandiant have tracked down an active campaign that uses a spoofed version of the legitimate Ukrainian-language tool &#8220;Civil Defense,&#8221; a crowdsourced mapping tool used to locate military recruiters. Attackers are using the fake version to perform dual malicious actions \u2014 dropping malware and delivering misinformation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The hybrid op, which researchers named UNC5812, uses a Telegram channel to lure perspective recruits to a download the malicious version of &#8220;Civil Defense&#8221; from a spoofed site, outside of the confines of Google Play. Once downloaded, the application drops Windows and Android malware.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Russian Opp Uses Malware With a Side of Social Engineering\">Russian Opp Uses Malware With a Side of Social Engineering<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Windows users who make their way to the fake &#8220;Civil Defense&#8221; site to download the tool will be delivered the Pronsis Loader, which then starts a chain to deliver a malicious mapping application called Sunspinner, as well as an infostealer called Purestealer.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Android users, on the other hand, get a common user backdoor called Craxsrat, in addition to Sunspinner.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Notably, the Civil Defense website also contains an unconventional form of social engineering designed to preempt user suspicions about APK delivery outside of the App Store and justify the extensive permissions required for the Craxsrat installation,&#8221; the report noted. &#8220;The website&#8217;s FAQ contains a strained justification for the Android application being hosted outside the App Store, suggesting it is an effort to &#8216;protect the anonymity and security&#8217; of its users, and directing them to a set of accompanying video instructions.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The video also provides instructions on how to disable Google Play Protect.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;While the Civil Defense website also advertises support for macOS and iPhones, only Windows and Android payloads were available at the time of analysis,&#8221; the report said.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Sunspinner, a decoy graphical user interface (GUI) application written using the Flutter framework, offers functionality aimed to convince victims that the application is legitimate.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Consistent with the functionality advertised on the [legitimate] Civil Defense website, Sunspinner is capable of displaying crowdsourced markers with the locations of the Ukrainian military recruiters, with an option for users to add their own markers,&#8221; according to the Google TAG analysis. But the fake map offers only fake locations: &#8220;However, despite possessing the limited functionality required for users to register and add markers, the displayed map does not appear to have any genuine user inputs. All markers present [were pulled from the attacker&#8217;s C2 and] were added on the same day by the same user.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Parallel Anti-Mobilization Effort Against Ukrainian Military\">Parallel Anti-Mobilization Effort Against Ukrainian Military<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In tandem with the espionage effort, the other goal of the Russian fake Civil Defense campaign is to deliver disinformation aimed at suppressing Ukraine&#8217;s military mobilization effort for the war. The malicious versions of Civil Defense&#8217;s site and Telegram have pushed out videos with incendiary, anti-Ukrainian-military titles like, &#8220;Unfair Actions From Territorial Recruitment Centers,&#8221; the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/cloud.google.com\/blog\/topics\/threat-intelligence\/russian-espionage-influence-ukrainian-military-recruits-anti-mobilization-narratives\" rel=\"noopener\">TAG Mandiant report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> added.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Users who click on the button provided by the Russian hacker-operated site to &#8220;Send Material,&#8221; ostensibly to discredit recruitment efforts, are automatically fed an attacker-controlled chat thread,&#8221; the report said. &#8220;Anti-mobilization content cross-posted to the group&#8217;s website and Telegram channel appears to be sourced from wider pro-Russian social media ecosystems. In at least one instance, a video shared by UNC5812 was shared a day later by the Russian Embassy in South Africa&#8217;s X account.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Russia has consistently used cyberattacks as part of its <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/russia-adjusts-cyber-strategy-for-the-long-haul-in-ukraine-war\" rel=\"noopener\">war strategy against Ukraine<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, as well as against other governments, including a recent distributed denial-of-service (DDoS) <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/russia-linked-hackers-attack-japan-govt-ports\" rel=\"noopener\">cyberattack campaign against shipping ports in Japan<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. Russian hackers have also been working feverishly to distribute <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/russians-pose-reputable-media-us-election-chaos\" rel=\"noopener\">disinformation ahead of the US 2024 election<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">. The threat group currently understood to be most actively, and directly, supporting Russian military activities in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/ics-ot-security\/-sandworm-group-is-russia-s-primary-cyber-attack-unit-in-ukraine\" rel=\"noopener\">Ukraine is Sandworm<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but, as this newly uncovered &#8220;Civilian Defense&#8221; campaign highlights, that&#8217;s just one of many hacker groups doing the Kremlin&#8217;s dirty work in cyberspace.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/threat-intelligence\/russia-kneecaps-ukraine-army-recruitment-spoofed-civil-defense-app\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ukrainian efforts to recruit new soldiers to serve in its<\/p>\n","protected":false},"author":12,"featured_media":5971,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-5970","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=2060%2C1274&ssl=1",2060,1274,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=300%2C186&ssl=1",300,186,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=640%2C396&ssl=1",640,396,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=640%2C396&ssl=1",640,396,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=1536%2C950&ssl=1",1536,950,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=2048%2C1267&ssl=1",2048,1267,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=1024%2C633&ssl=1",1024,633,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/10\/russia-kneecaps-ukraine-army-recruitment-with-spoofed-civil-defense-app.jpg?fit=2060%2C1274&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5970","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=5970"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/5970\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/5971"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=5970"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=5970"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=5970"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}