SBU exposes russian intelligence attempts to penetrate Armed Forces' planning operations system.pdf
ID: f2c16e5f-dc94-4212-b60c-648569199047
STIX ID: report--f2c16e5f-dc94-4212-b60c-648569199047
Threat Score
90/100
Uploaded: 2026-08-14
Published Date: 2023-08-16
Last Modified Date: 2023-08-16
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SBU technical report attributes a prolonged cyber operation to Russian military intelligence (Sandworm) that sought to compromise Android devices used by Ukrainian military via exposed ADB (port 5555). Multiple custom malware families were documented—providing persistence (netd replacement), remote access (Tor hidden services, Dropbear/SSH), data collection (including Starlink telemetry), and Mirai-type downloaders—along with network scan examples, C2 IPs and numerous file hashes; the operation was detected and neutralized.
