logo

Sandworm__2017__TeleBots_are_back_supply-chain_attacks_against_Ukraine.pdf

ID: 3d239eea-c241-4abc-a008-04e84af23d7d

STIX ID: report--3d239eea-c241-4abc-a008-04e84af23d7d

Threat Score

85/100

Uploaded: 2026-08-19

Published Date: 2017-10-27

Last Modified Date: 2017-10-27

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
The report describes the TeleBots threat actor's evolving cyber campaigns against Ukraine, detailing multiple ransomware families (Diskcoder.C/NotPetya, AESNI.C, KillDisk), a supply-chain infection via the ME Doc software, credential-dumping and lateral movement tools, and covert C2 infrastructure (Telegram Bot API and Tor relay) along with IoCs and indicative artifacts.