Operation Potao Express: Analysis of a cyber-espionage toolkit

Attackers spying on high-value targets in Ukraine, Russia and Belarus, and their TrueCrypt-encrypted data We presented our initial findings based on research into the Win32/Potao malware family in June, in our CCCC 2015 presentation in Copenhagen. Today, we are releasing the full whitepaper on the Potao malware with additional findings, the cyberespionage campaigns where it was … More Operation Potao Express: Analysis of a cyber-espionage toolkit

Back in BlackEnergy*: 2014 Targeted Attacks in Ukraine and Poland

A large number of state organisations and private businesses from various industry sectors in Ukraine and Poland have been targeted in recent attacks using malware designed for network discovery and remote code execution, and for collecting data from targets’ hard drives. What makes these attacks interesting – aside from the tense current geopolitical situation in … More Back in BlackEnergy*: 2014 Targeted Attacks in Ukraine and Poland