BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Russian Hackers Accelerate AI-Driven Cyber Attacks on Ukraine 2025

Russian Hackers Intensify AI-Driven Cyber Attacks on Ukraine in Early 2025

  • Russian Hackers increased use of Artificial Intelligence (AI) in cyber attacks against Ukraine in early 2025.
  • There were 3,018 cyber incidents reported in the first half of 2025, up from 2,575 in the latter half of 2024.
  • Malware such as WRECKSTEEL and phishing campaigns targeting defense and government sectors have been observed using AI-generated tools.
  • Russia-linked groups exploited vulnerabilities in Roundcube and Zimbra email software to steal credentials without user interaction.
  • Attackers increasingly use legitimate services like Dropbox and Google Drive to host malware and phishing content, complicating defense efforts.

The Ukrainian State Service for Special Communications and Information Protection (SSSCIP) reported that Russian hackers have advanced their use of artificial intelligence in cyber attacks during the first half of 2025. These attacks affected various sectors in Ukraine, including military and local government institutions.

- Advertisement -

According to SSSCIP, 3,018 cyber incidents were recorded in this period, marking an increase from 2,575 incidents in the second half of 2024. The agency noted a rise in attacks targeting local authorities and military bodies, while incidents against government and energy sectors declined.

The agency highlighted the use of AI not only in generating phishing messages but also in developing malware. One example is the WRECKSTEEL malware, linked to the UAC-0219 group, used to target state administration agencies and critical infrastructure. “There is evidence to suggest that the PowerShell data-stealing malware was developed using AI tools,” SSSCIP stated.

Other phishing campaigns involve various threat actor clusters, including UAC-0218 distributing the HOMESTEEL malware through booby-trapped RAR archives, and UAC-0226 targeting defense innovation organizations with the GIFTEDCROOK stealer. Additionally, UAC-0227 targets local governments and infrastructure using phishing techniques to deliver Amatera and Strela Stealers. The Sandworm-associated UAC-0125 group sends emails impersonating security software to distribute a C# backdoor called Kalambur.

SSSCIP also reported that the Russia-linked group APT28 (UAC-0001) exploited security flaws in webmail applications Roundcube and Zimbra. These exploits, known as zero-click attacks, allowed attackers to steal credentials and contact information without user interaction by injecting malicious code through application programming interfaces.

- Advertisement -

“Another method…was to create hidden HTML blocks where login information stored in the browser would be auto-filled and then exfiltrated,” the agency explained.

The report confirmed that Russian cyber groups continue to coordinate their digital attacks with physical military actions, with Sandworm (UAC-0002) targeting areas such as energy, defense, internet providers, and research.

Furthermore, an increasing trend involves abusing legitimate online platforms like Dropbox, Google Drive, OneDrive, Bitbucket, and Telegram to host malware, phishing pages, or facilitate data theft. “The use of legitimate online resources for malicious purposes is not a new tactic,” SSSCIP noted, “However, the number of such platforms exploited by Russian hackers has been steadily increasing in recent times.”

For more information, visit the official SSSCIP report.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Ex-FTX engineer Nishad Singh fined $3.7 million

Former FTX head of engineering Nishad Singh settled a Commodity Futures Trading Commission (CFTC)...

Tether’s Jesse Spiro to Chair $100M Crypto Super PAC

Tether's Head of Government Affairs, Jesse Spiro, will chair the crypto-funded Fellowship PAC ahead...

CERT-UA Impersonated, New RAT Attack Hits Ukraine

The Computer Emergency Response Team of Ukraine (CERT-UA) was impersonated in a phishing campaign...

Binance Launches Oil and Gas Futures with 100x Leverage

Binance has officially launched trading for oil and natural gas futures contracts, completing its...

Franklin Templeton Buys 250 Digital to Launch Crypto Unit

Franklin Templeton is establishing a dedicated crypto unit, Franklin Crypto, through the acquisition of...

Must Read

7 Best Crypto To Invest In This Year

Investing in cryptocurrencies has become a popular way for people to diversify their investment portfolio and make potential profits.However, with so many cryptocurrencies available...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading