October 3, 2023

Ukraine’s CERT-UA has issued a warning about a cyber-attack orchestrated by the notorious Russian threat actor APT28. Targeting a critical power infrastructure facility in Ukraine.

CERT-UA detected the attempted breach on September 5, 2023. The attackers employed a sophisticated method to infiltrate their target. They crafted a scheme involving bulk emails sent from a fabricated address, each containing a link to a seemingly innocuous ZIP archive. This could have potentially granted the attackers unauthorized access to the organization’s systems and sensitive data.

What made this attack particularly insidious was the fact that the perpetrators leveraged legitimate services such as Mockbin and standard software functions to execute their malicious plan.


Ukraine’s cybersecurity services acted swiftly and effectively to thwart the impending attack, thereby safeguarding the integrity and security of the targeted critical infrastructure.

The threat actor intention is to enable future operations rather than an immediate attempt to disrupt critical infrastructure This emphasized that this modus operandi aligns more with APT28, as opposed to their Russian counterpart, Sandworm.

To shed more lights on the APT28, also known by aliases such as Pawn Storm, Fancy Bear, and BlueDelta, has long been associated with Russian special services, specifically Russia’s GRU Unit 26165. The group’s track record of cyber-espionage activities has raised concerns not only in Ukraine but across the international cybersecurity community.

This is not the first time APT28 has targeted Ukrainian organizations. CERT-UA had previously detected attempted attacks by the group in April, June, and July of 2023. These repeated incursions underscore the persistent threat that APT28 poses to Ukraine’s cybersecurity landscape.

As Ukraine continues to grapple with cyber threats to its critical infrastructure, international cooperation and vigilance remain essential in safeguarding against further attacks and ensuring the security of vital systems.


CERT-UA’s prompt detection and response serve as a testament to the importance of proactive cybersecurity measures in an increasingly interconnected and vulnerable digital landscape.

Indicators of Compromise

  • ab7d21d81de1039345f9b08d5b64b3c015ea70a15d7ff1194f5f073ca1fbbe23 
  • 8c268cf8d0bbe3ab1f25f5fdc205c14e30d78a63cc43c5ffbd0733e44fe31b5c 
  • 47569fbf80dda804b4ea00c5678d4d98113c3b1f2e52630d191524c615b885a8 
  • aab6b46c209305b4fef7c7bfc16cc9ada1e937ef322cf9b3f5107d65fe59eabb 
  • 1c47e40a2f4dc93ed5b8253278799a4cd70890ec968512ade54b5767707f9a7b 
  • 561ab624c7214e3b21edd97bf575d5ec0ff7da25b1ae374e616f27a99ca0b77b 
  • 8c268cf8d0bbe3ab1f25f5fdc205c14e30d78a63cc43c5ffbd0733e44fe31b5c 
  • 47569fbf80dda804b4ea00c5678d4d98113c3b1f2e52630d191524c615b885a8 
  • aab6b46c209305b4fef7c7bfc16cc9ada1e937ef322cf9b3f5107d65fe59eabb 
  • 4b4fbfb0f201d6b80f22cbf1c8d6b1fb2e1a155ce37d426065167e10239062aa 
  • 9b6b926b7089d401a6f73094167a6144dd3f6e485128cc28b449d917da79018a 
  • af4d7ad40e505d047f9df078ef3f6c7e0207c882dc91705e2f4190cc7d2360ce 
  • d03373be2435af1966bfdfe51ae6d0038e4d4f3c353b63fea41144d144547121 

