CERT-UA records new cyberattack tactics and AI use against Ukraine - State Special Communications Service

 • 3292 переглядiв

The State Special Communications Service reported changes in cyberattacks against Ukraine in the first half of 2025. The enemy is using new tactics, involving "fresh blood" and complex tools for data theft, including AI for generating PowerShell scripts.

The State Special Communications Service reported that in the first half of 2025, CERT-UA recorded a number of new activities in cyberattacks against Ukraine – the enemy is changing tactics and attracting "fresh blood", and also beginning to use complex tools for data theft. This is reported by UNN with reference to the State Special Communications Service.

Details

In the analytical report "Russian Cyber Operations" for the first half of 2025, the State Special Communications Service states a radical change in tactics, techniques and procedures by the attackers. According to CERT-UA specialists, these changes indicate a decrease in the effectiveness of established attack methods – probably due to increased resistance from the Ukrainian side – so the enemy is experimenting with new approaches and personnel.

Cyber specialists of the DIU paralyzed the work of the Russian fast payment banking system - source25.09.25, 12:12

The document of the State Special Communications Service describes in detail several groups, including the group designated UAC-0219. This group uses the malicious tool WRECKSTEEL, capable of stealing files with predefined extensions and taking screenshots, which are then uploaded to the attackers' servers. CERT-UA also notes that the attackers are likely using artificial intelligence to generate PowerShell scripts, which increases the speed and flexibility of attacks.

The report emphasizes that the activation of "fresh" operators and the modernization of tools make attacks more variable – this requires the cybersecurity sector to adapt methods of detecting and preventing incidents. CERT-UA calls on government agencies and the private sector to strengthen monitoring, update response procedures, and promptly apply indicators of compromise from the analytical report.

CERT-UA detected cyberattacks on the Defense Forces via malicious XLL files01.10.25, 16:41

Popular
In Kyiv, the death toll from Russian attacks has risen to seven, with 46 injured

 • 12339 переглядiв

Taylor Swift released Encore for her hit album Showgirl

 • 11600 переглядiв

Kate Moss recreated her iconic Glastonbury look 21 years later

 • 15800 переглядiв

An Audi electric car set a Guinness World Record by traveling 1,338 km on a single charge

 • 6742 переглядiв

News by theme
Sumy-Kyiv train to change route due to threat of Russian attacks: possible delays

 • 3965 переглядiв

Switzerland restricts protection status for Ukrainians from certain regions

 • 14172 переглядiв

Kalchyk River in Mariupol turned into a swamp due to sewage discharge - city council

 • 2704 переглядiв

Mayor of Vyshhorod suspected of embezzling over UAH 6.6 million in budget funds

 • 3786 переглядiв

Man brutally murdered 16-year-old girl in Kirovohrad region - National Police

 • 2602 переглядiв