No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Newly identified APT group’s motives in Ukraine baffle researchers

May 12, 2023
in Protection
0
Newly identified APT group’s motives in Ukraine baffle researchers



Several advanced persistent threat attacks carried out across Ukraine between 2020 and 2022 have been linked to the same group of actors: a mystery entity whose allegiances are unclear.

Malwarebytes published a blog post on Wednesday detailing attacks it attributes to the group, dubbed Red Stinger.

It said Red Stinger was the same group Kaspersky recently revealed as being behind attacks last year on government, agriculture, and transportation organizations in Donetsk, Lugansk, and Crimea. Kaspersky calls the group Bad Magic.

Malwarebytes’ research found Red Stinger/Bad Magic’s attacks stretched back to 2020, and occurred in centers other than just Donetsk, Lugansk, and Crimea (which was annexed by Russia in 2014).

“Military, transportation and critical infrastructure were some of the entities being targeted, as well as some involved in the September [2022] East Ukraine referendums,” the post said.

“Depending on the campaign, attackers managed to exfiltrate snapshots, USB drives, keyboard strokes, and microphone recordings.”

The researchers said because of the contrasting nature of the attacks they have linked to the group, they couldn’t attribute Red Stinger to a specific country.

“Any of the involved countries [in the Russia/Ukraine war] or aligned groups could be responsible, as some victims were aligned with Russia, and others were aligned with Ukraine,” the blog stated.

An example of the baffling diversity of the targets of Red Stinger’s attacks occurred in September last year when Russia held referendums in Luhansk, Donetsk, Zaporizhzhia and Kherson seeking support for its occupation.

The group targeted several election officials involved in the Russian referendums, but during the same operation it also targeted a Ukrainian library in the city of Vinnytsia.

“What is clear is that the principal motive of the attack was surveillance and data gathering. The attackers used different layers of protection, had an extensive toolset for their victims, and the attack was clearly targeted at specific entities,” the researchers wrote.

“Perhaps in the future, further events or additional activity from the group can shed light on the matter.”

The researchers also uncovered evidence that, at some point, Red Stinger had infected its own machines. It was unclear whether that had been done by mistake or to carry out testing, they said, although the group’s use of the names TstSCR and TstVM to identify two of its victims possibly suggested the action was a test.

Red Stinger’s attack chain involves using malicious installer files to activate DBoxShell—malware that utilizes cloud storage services as a command-and-control mechanism—onto compromised Windows machines.

A Microsoft Software Installer (MSI) file is downloaded through a Windows shortcut file contained within a ZIP archive.

“This stage serves as an entry point for the attackers, enabling them to assess whether the targets are interesting or not, meaning that in this phase they will use different tools,” the researchers said.

In the exfiltration phase of its operations, Red Stinger has used custom tools to steal data which may include a combination of screenshots, content from USB drives, keystroke logs and microphone recordings. The exfiltration phase of Red Stinger’s attacks has been known to last up to several months.

Editorial Team

Editorial Team

Related Posts

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale
Protection

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

March 25, 2026
The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon's Spring Sale
Protection

The DJI Osmo 360 Essential Combo Is Over $200 Off for Amazon’s Spring Sale

March 25, 2026
This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale
Protection

This Fire TV Stick Is Already 50% Off for the Amazon Spring Sale

March 25, 2026
Spotify's New 'SongDNA' Is Actually a Great Way to Learn More About Your Music
Protection

Spotify’s New ‘SongDNA’ Is Actually a Great Way to Learn More About Your Music

March 25, 2026
The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor
Protection

The Best Ways to Make Use of Those Spare USB Ports on Your TV or Monitor

March 25, 2026
Ultrahuman’s New Ring Pro Is Finally Available in the US
Protection

Ultrahuman’s New Ring Pro Is Finally Available in the US

March 25, 2026
Load More
Next Post
Live news: US consumer sentiment tumbles as worries about economy grow

Live news: US consumer sentiment tumbles as worries about economy grow

Popular News

  • Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    Oil prices fall on reports of a U.S. ceasefire proposal with Iran

    0 shares
    Share 0 Tweet 0
  • BlackRock’s Fink on why he won’t cash out private-credit investors: ‘Those are the rules, live with it.’

    0 shares
    Share 0 Tweet 0
  • L&G enters $1bn strategic partnership with Enosis Capital

    0 shares
    Share 0 Tweet 0
  • US gasoline prices to rise after attack on Iran, analysts warn

    0 shares
    Share 0 Tweet 0
  • Majority of Fitch-rated sub lines have AA+ rating

    0 shares
    Share 0 Tweet 0

Latest News

CFTC Chief Launches Innovation Task Force to Reshape Crypto

CFTC Chief Launches Innovation Task Force to Reshape Crypto

March 25, 2026
0

Commodity Futures Trading Commission (CFTC) Chair Michael Selig officially launched the agency’s Innovation Task Force on Tuesday, appointing senior adviser...

Former SEC chair Jay Clayton says regulators would scrutinize trading ahead of Trump post

Former SEC chair Jay Clayton says regulators would scrutinize trading ahead of Trump post

March 25, 2026
0

Jay Clayton said regulators would likely examine the unusual burst of trading activity early Monday that preceded a market-moving social...

Semi-liquid funds hit almost $60bn in AUM despite scrutiny

Semi-liquid funds hit almost $60bn in AUM despite scrutiny

March 25, 2026
0

Global open-ended private credit funds have reported monthly growth over the past few years, with assets under management rising to...

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

This 15-Inch M4 MacBook Air Is $300 Off for the Amazon Big Spring Sale

March 25, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.