Uptime Hamster: 15d 4h 29mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza Operation Groundbait

Operation Groundbait

0 incidentes 0 paises 0 sectores apt Russia Ultimo: -
Aliases: Groundbait
Ver en IntelTracker → APTTrail →
Operation Groundbait was a cyber espionage campaign that publicly emerged in 2016, though its associated Prikormka malware was active since at least 2008. The campaign was initially assessed with moderate confidence to be operated by attackers from within Ukraine, primarily motivated by politically-aligned cyber surveillance. It notably targeted anti-government separatists in the self-declared Donetsk and Luhansk People's Republics, as well as Ukrainian government officials, politicians, and journalists. While the distinct Operation Groundbait activities largely ceased by 2017, the actor behind it continued to evolve its toolset under other monikers, such as CloudWizard and CommonMagic, and is currently suspected to be state-sponsored by Russia. The campaign is recognized for being one of the first publicly known instances of Ukrainian-originated malware used in targeted attacks.

Aliases del actor

Groundbait

Actores similares

apt-groundbaitactor · 1Operation Wocaoapt · 1influence-operationsactor · 1Operation Ghostwriterapt · 0Operation C-Majorapt · 0Operation Silent Skimmerapt · 0Operation Cobalt Whisperapt · 0Operation RusticWebapt · 0Operation LiberalFaceapt · 0Operation Olympic Gamesapt · 0
Motivacion