TeleBots are back: Supply-chain attacks against Ukraine
ID: 4e1b5a67-4a9b-42a9-8374-323a2f8f434e
STIX ID: report--4e1b5a67-4a9b-42a9-8374-323a2f8f434e
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2017-06-30
Last Modified Date: 2017-06-30
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes the TeleBots group's supply-chain and ransomware campaigns in Ukraine (2016–2017), their use of compromised ME Doc software to spread multiple ransomware families and backdoors, and the associated indicators of compromise and infrastructure.
