Large-scale espionage cyberattack on the defense sector of Ukraine

20 March 2025 2 minutes Author: Newsman

Ukrainian defense enterprises and military facilities have become targets of targeted cyberattacks. In March 2025, numerous cases of the DarkCrystal RAT malware being distributed through widely used instant messengers were recorded, which poses a significant threat to the country’s security.

Cybercriminals are sending archives that supposedly contain official documents related to meetings and orders. The sending is carried out on behalf of real contacts whose accounts were previously hacked. The archives contain PDF files and executable programs, among which the DarkTortilla malware was found, which acts as a cryptor/loader for the subsequent launch of the DarkCrystal RAT (DCRAT) spyware.

Attackers are actively changing the subject matter of phishing messages, adapting it to current topics in the defense sector, in particular, to drones and electronic warfare equipment. The use of instant messengers significantly complicates the control of the flow of information and opens up additional opportunities for attacks.

DarkCrystal RAT is a powerful tool for remote control of infected devices, which allows attackers to access confidential information, execute arbitrary commands and carry out espionage operations. Recently, the methods of delivery of this software have become increasingly sophisticated, in particular due to the trust in compromised accounts. The surge in espionage attack activity indicates the need to strengthen cybersecurity measures, raise awareness among defense personnel and thoroughly check all received files.

Malicious campaigns using DarkCrystal RAT threaten the defense sector of Ukraine. The use of popular instant messengers for attacks indicates a growing level of cyber threats. It is important to observe information hygiene, not open suspicious files and report detected threats in a timely manner.

Other related articles
News
Read more
Western Alliance Bank Cyberattack
Western Alliance Bank Cyberattack Western Alliance Bank has announced a massive data breach affecting 21,899 customers. Attackers affiliated with the Clop group exploited a vulnerability in a third-party file transfer software to gain access to sensitive information, including social security numbers, bank account details and passport details. The bank has officially reported the breach to regulators in Maine and California, confirming that it was the victim of an attack due to a flaw in its secure file sharing software. The name of the software is not disclosed, but the Clop hackers have previously reported using Cleo, which is used by many organizations. According to Western Alliance, the unauthorized access occurred from October 12 to 24, 2024, and the bank only learned about it on January 27, 2025. In response, the victims were offered a one-year subscription to protect their personal data. Clop is one of the most active cybercrime groups, specializing in data theft through vulnerabilities in file-sharing services. They have already carried out attacks on MOVEit, GoAnywhere and Accellion, stealing information from thousands of companies. Clop attacks have previously affected Hewlett Packard Enterprise and Thomson Reuters, which are currently investigating possible compromise of their systems by Cleo. Western Alliance Bank data leak demonstrates the vulnerability of financial institutions to cybercrime. The bank assures that it is strengthening security measures, but hacker attacks on the financial sector continue, highlighting the need for stricter cyber-defense protocols. #### SEO-text Western Alliance Bank data leak: Clop hackers gained access to confidential information of 21,899 customers through a vulnerability in a file-sharing program. The bank has offered a year-long protection of personal data, but the threat to cybersecurity in the financial sector remains high.
120
News
Read more
Alphabet challenges Starlink
Alphabet has introduced a laser alternative to Starlink: the new Taara project provides internet via laser beams, allowing for quick installation, high speed (up to **20 Gbps**) and effective coverage of remote regions.
127
News
Read more
Ukrainian drone with a range of 3,000 km has passed the test
A Ukrainian drone with a range of 3000 km has successfully passed the tests. Its capabilities significantly affect the course of military operations, allowing it to attack strategic targets in the deep rear of Russia. Successful tests of a drone capable of reaching Novosibirsk emphasize the rapid development of Ukrainian military technologies.
134
Found an error?
If you find an error, take a screenshot and send it to the bot.