Operation Groundbait
0 incidentes
0 paises
0 sectores
apt Russia Ultimo: -
Aliases: Groundbait
Operation Groundbait was a cyber espionage campaign that publicly emerged in 2016, though its associated Prikormka malware was active since at least 2008. The campaign was initially assessed with moderate confidence to be operated by attackers from within Ukraine, primarily motivated by politically-aligned cyber surveillance. It notably targeted anti-government separatists in the self-declared Donetsk and Luhansk People's Republics, as well as Ukrainian government officials, politicians, and journalists. While the distinct Operation Groundbait activities largely ceased by 2017, the actor behind it continued to evolve its toolset under other monikers, such as CloudWizard and CommonMagic, and is currently suspected to be state-sponsored by Russia. The campaign is recognized for being one of the first publicly known instances of Ukrainian-originated malware used in targeted attacks.