Spilnota Detector Media
Русскій фейк, іді на***!

Disclosure Ukrainians receive letters with harmful links on behalf of the State Emergency Service of Ukraine

The cyberattack with dangerous emails was detected by specialists from the cybersecurity unit of “Ukrzaliznytsia” (Ukrainian railway). The subject of the letters is “How to recognize a kamikaze drone”, and they allegedly arrive on behalf of the State Emergency Service of Ukraine (DSNS) from morgunov.a@dsns.com[.]ua.

The attachment to the letter contains the RAR archive "shahed-136.rar" with the PPSX document "shahed.ppsx". If you open it, the file "WibuCm32.dll" will be downloaded to the device. It is classified as DolphinCape malware. The main functionality of the program is to collect information about the computer, run EXE/DLL files, as well as create and exfiltrate screenshots.

NGO “Detector Media” has been working for our readers for over 20 years. In times of elections, revolutions, pandemics and war, we continue to fight for quality journalism. Our experts develop media literacy of the audience, advocate for the rights of journalists, and refute Russian disinformation.

“Detector Media” resumes the work of our Community and invites those who believe that the media should be better: more professional, truthful and transparent.