Hackers attempt to infiltrate Ukrainian tech company with backdoor malware, Talos says
Full article473 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The attack could have been part of an attempt to compromise the software supply chain, the researchers said.
Attackers targeted a large, unnamed software development company in Ukraine that services various state entities with a “fairly uncommon” piece of malware in recent weeks, researchers with Cisco Talos said Thursday.
The unknown hackers used a slightly modified version of an open-source backdoor named “GoMet,” the researchers said, that at least two sophisticated hacking groups have used since 2020.
Despite the fact that the Talos researchers found no indication that the attackers successfully exploited the tool, they are concerned nonetheless, they said.
“As this firm is involved in software development, we cannot ignore the possibility that a supply chain-style attack might have been this campaign’s end goal,” the researchers said.
Cyberattacks have increasingly bombarded both private and government entities in Ukraine since the first Russian invasion of Ukraine in 2014 and as part of the war that began Feb. 24. Ukrainian officials who track cyber “incidents” recorded at least 64 in second quarter of 2022, up from 40 the previous quarter, officials said in a recent report with details of new and ongoing attacks emerging regularly.
A successful attack on a software provider could “be leveraged in a variety of ways including deeper access or to launch additional attacks, including the potential for software supply chain compromise,” the researchers wrote.
“Ukraine is still facing a well-funded, determined adversary that can inflict damage in a variety of ways,” they said. “This is just the latest example of those attempts.”
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/ukraine-supply-chain-attack-malware-gomet-backdoor/