Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Russian Hackers Linked To Attack Targeting Ukrainian Government

Russian Hackers Linked To Attack Targeting Ukrainian Government

Image: UP9 (CC BY-SA 3.0)

The National Security and Defense Council of Ukraine (NSDC) has linked Russian-backed hackers to attempts to breach state agencies after compromising the government’s document management system.

The System of Electronic Interaction of Executive Bodies (SEI EB) hacked in this attack is used by most public authorities to share documents, as the country’s national security and defense agency explained.

“The NCCC at the NSDC of Ukraine warns of a cyberattack on the document management system of state bodies,” an advisory published earlier today says.

“The methods and means of carrying out this cyberattack allow to connect it with one of the hacker spy groups from the Russian Federation.”

Also Read: In Case You Didn’t Know, ISO 27001 Requires Penetration Testing

The Russian-linked threat actors attempted to use the document sharing system “to disseminate malicious documents,” with the end goal of infecting systems belonging to Ukrainian public authorities.

Malicious documents uploaded to the SEI EB system by the attackers bundled macros designed to silently download and deploy a malware payload onto the targets’ computers.

Once it infected the systems, the malware would’ve allowed the threat actors to control the victims’ machines remotely.

“According to the scenario, the attack belongs to the so-called supply chain attacks,” the NSDC added.

“It is an attack in which attackers try to gain access to the target organization not directly, but through the vulnerabilities in the tools and services it uses.”

While the Ukrainian cybersecurity agency did not attribute this attack to a specific Russian APT group, it did provide indicators of compromise (IOCs) to allow security admins to detect and block future attacks using the same infrastructure.

DDoS attacks also linked to Russian actors

On Monday, the NSDC also accused threat actors with Russian-ties of launching DDoS attacks on Ukrainian government sites, including those of the Security Service of Ukraine, and the National Security and Defense Council of Ukraine.

It is believed that Egregor threat actors launched the attacks in retaliation to arrests of alleged Egregor ransomware operation members two weeks ago.

Also Read: 4 Considerations In The PDPA Singapore Checklist: The Specifics

One day after the Security Service of Ukraine (SBU) published a press release on the Egregor arrests, the SBU’s website was hit by a DDoS attack and became inaccessible.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us