logo

TeleBots are back: Supply-chain attacks against Ukraine

ID: 4e1b5a67-4a9b-42a9-8374-323a2f8f434e

STIX ID: report--4e1b5a67-4a9b-42a9-8374-323a2f8f434e

Threat Score

78/100

Uploaded: 2026-08-19

Published Date: 2017-06-30

Last Modified Date: 2017-06-30

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes the TeleBots group's supply-chain and ransomware campaigns in Ukraine (2016–2017), their use of compromised ME Doc software to spread multiple ransomware families and backdoors, and the associated indicators of compromise and infrastructure.