CERT-UA records new cyberattack tactics and AI use against Ukraine - State Special Communications Service

 • 3276 переглядiв

The State Special Communications Service reported changes in cyberattacks against Ukraine in the first half of 2025. The enemy is using new tactics, involving "fresh blood" and complex tools for data theft, including AI for generating PowerShell scripts.

The State Special Communications Service reported that in the first half of 2025, CERT-UA recorded a number of new activities in cyberattacks against Ukraine – the enemy is changing tactics and attracting "fresh blood", and also beginning to use complex tools for data theft. This is reported by UNN with reference to the State Special Communications Service.

Details

In the analytical report "Russian Cyber Operations" for the first half of 2025, the State Special Communications Service states a radical change in tactics, techniques and procedures by the attackers. According to CERT-UA specialists, these changes indicate a decrease in the effectiveness of established attack methods – probably due to increased resistance from the Ukrainian side – so the enemy is experimenting with new approaches and personnel.

Cyber specialists of the DIU paralyzed the work of the Russian fast payment banking system - source25.09.25, 12:12

The document of the State Special Communications Service describes in detail several groups, including the group designated UAC-0219. This group uses the malicious tool WRECKSTEEL, capable of stealing files with predefined extensions and taking screenshots, which are then uploaded to the attackers' servers. CERT-UA also notes that the attackers are likely using artificial intelligence to generate PowerShell scripts, which increases the speed and flexibility of attacks.

The report emphasizes that the activation of "fresh" operators and the modernization of tools make attacks more variable – this requires the cybersecurity sector to adapt methods of detecting and preventing incidents. CERT-UA calls on government agencies and the private sector to strengthen monitoring, update response procedures, and promptly apply indicators of compromise from the analytical report.

CERT-UA detected cyberattacks on the Defense Forces via malicious XLL files01.10.25, 16:41

Popular
What is celebrated on September 5 in Ukraine and around the world

 • 7640 переглядiв

Court Orders Trump Administration to Reveal Creators of Secret $1.8 Billion Fund

 • 5496 переглядiв

A private spacecraft approached NASA’s doomed telescope, but could no longer save it

 • 8368 переглядiв

Not a ricochet: experts believe a U.S. munition struck a wedding in Iran – Reuters

 • 8704 переглядiв

News by theme
Sumy-Kyiv train to change route due to threat of Russian attacks: possible delays

 • 3953 переглядiв

Switzerland restricts protection status for Ukrainians from certain regions

 • 14160 переглядiв

Kalchyk River in Mariupol turned into a swamp due to sewage discharge - city council

 • 2695 переглядiв

Mayor of Vyshhorod suspected of embezzling over UAH 6.6 million in budget funds

 • 3775 переглядiв

Man brutally murdered 16-year-old girl in Kirovohrad region - National Police

 • 2600 переглядiв