Sandworm__2017__TeleBots_are_back_supply-chain_attacks_against_Ukraine.pdf
ID: 3d239eea-c241-4abc-a008-04e84af23d7d
STIX ID: report--3d239eea-c241-4abc-a008-04e84af23d7d
Threat Score
85/100
Uploaded: 2026-08-19
Published Date: 2017-10-27
Last Modified Date: 2017-10-27
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report describes the TeleBots threat actor's evolving cyber campaigns against Ukraine, detailing multiple ransomware families (Diskcoder.C/NotPetya, AESNI.C, KillDisk), a supply-chain infection via the ME Doc software, credential-dumping and lateral movement tools, and covert C2 infrastructure (Telegram Bot API and Tor relay) along with IoCs and indicative artifacts.
