logo

SBU exposes russian intelligence attempts to penetrate Armed Forces' planning operations system.pdf

ID: f2c16e5f-dc94-4212-b60c-648569199047

STIX ID: report--f2c16e5f-dc94-4212-b60c-648569199047

Threat Score

90/100

Uploaded: 2026-08-14

Published Date: 2023-08-16

Last Modified Date: 2023-08-16

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SBU technical report attributes a prolonged cyber operation to Russian military intelligence (Sandworm) that sought to compromise Android devices used by Ukrainian military via exposed ADB (port 5555). Multiple custom malware families were documented—providing persistence (netd replacement), remote access (Tor hidden services, Dropbear/SSH), data collection (including Starlink telemetry), and Mirai-type downloaders—along with network scan examples, C2 IPs and numerous file hashes; the operation was detected and neutralized.