cyber daily logo

Breaking news and updates daily. Subscribe to our Newsletter

Breaking news and updates daily. Subscribe to our Newsletter X facebook linkedin Instagram Instagram

Threat groups leveraging Russia-Ukraine conflict spreading malware

Check Point Software analysts have seen an increase of threat groups leveraging war-themed documents on the Russia-Ukraine conflict to spread malware and lure victims into cyber espionage.

user iconReporter
Mon, 04 Apr 2022
Threat groups leveraging Russia-Ukraine conflict spreading malware
expand image

The threat intelligence arm of the organisation, Check Point Research (CPR), revealed three APT groups named El Machete, Lyceum and SideWinder were found to be running spear-phishing campaigns in five countries.

Key findings:

  • CPR counts victims in Nicaragua, Venezuela, Israel, Saudi Arabia and Pakistan.
  • Victims identified span government, financial and energy sectors.
  • CPR continues to see a rise in overall cyber attacks on both Ukraine and Russia, +39 per cent and +22 per cent respectively, since the beginning of war.

According to Sergey Shykevich, threat intelligence group manager at Check Point Software, the CPR team are seeing a variety of APT campaigns that utilises the current war for malware distribution right now.


“The campaigns are highly targeted and sophisticated, focusing on victims in the government, financial and energy sectors.

“In our newest report, we profile and bring examples from three different APT groups, who all originate in different parts of the world, that we caught orchestrating these spear-phishing campaigns.

“We studied the malware involved closely and found capabilities that span keylogging, screenshotting and more,” Shykevich said.

The attackers used decoys ranging from official-looking documents to news articles and job postings. After examining the lure documents, CPR found malware capable of keylogging, screenshotting and executing commands. CPR believes the motivation behind these recent cyber espionage campaigns is to steal sensitive information from governments, banks and energy companies.

The table below summarises each APT group’s origin, target sector and target countries.

Malware capabilities

CPR studied the malware laced by each of the three APT groups, specifically for these cyber espionage activities.

Capabilities include:

  • Keylogging: steals everything you enter using the keyboard;
  • Credential collection: collects credentials stored in Chrome and Firefox browsers;
  • File collection: collects information about the files on each drive and collect file names and file sizes, allowing theft of specific files;
  • Screenshotting;
  • Clipboard data collection; and
  • Command execution.

Attack Methodologies

El Machete

  • Spear-phishing email with text about Ukraine.
  • Attached Word document with article about Ukraine.
  • Malicious macro inside the document drops a sequence of files.
  • Malware downloaded to the PC.


  • Email with content about war crimes in Ukraine and link to malicious document hosted on a website.
  • The document executes a macro code when the document is closed.
  • Exe file is saved to the PC.
  • Next time you restart your PC the malware runs.


  • Malicious document is opened by the victim.
  • When it’s opened, the document retrieves a remote template from an actor-controlled server.
  • The external template that’s downloaded is an RTF file, which exploits the CVE-2017-11882 vulnerability.
  • Malware on the PC of the victim.

Russia-Ukraine-themed documents become lure of choice

El Machete was spotted sending spear-phishing emails to financial organisations in Nicaragua, with an attached Word document titled “Dark plans of the neo-Nazi regime in Ukraine”. The document contained an article written and published by Alexander Khokholikov, the Russian Ambassador to Nicaragua that discussed the Russo-Ukrainian conflict from the perspective of the Kremlin.


In mid-March, an Israeli energy company received an email from the address inews-reporter@protonmail[.]com with the subject Russian war crimes in Ukraine.

The email contained a few pictures taken from public media sources and contained a link to an article hosted on the news-spot[.]live domain. The link in the email leads to a document which contains the article Researchers gather evidence of possible Russian war crimes in Ukraine published by The Guardian. The same domain hosts a few more malicious documents related Russia as well as the Russia-Ukraine war, such as a copy of an article by The Atlantic Council from 2020 on Russian nuclear weapons, and a job posting for an Extraction/Protective Agent agent in Ukraine.


SideWinder’s malicious document, which also exploits the Russia-Ukraine war, was uploaded to VirusTotal (VT) in mid-March. Judging by its content, the intended targets are Pakistani entities; the bait document contains the document of the National Institute of Maritime Affairs of Bahria University in Islamabad and is titled “Focused talk on Russian Ukraine Conflict Impact on Pakistan”. This malicious document uses remote template injection. When it’s opened, the document retrieves a remote template from an actor-controlled server.

Latest overall cyber attack numbers on Ukraine, Russia and NATO countries

Recently, Check Point Research (CPR) released an update on cyber attack trends throughout the current Russia-Ukraine war. One month after the war started on 24 February 2022, both Russia and Ukraine saw increases in cyberattacks of 10 per cent and 17 per cent, respectively.

CPR has also observed a 16 per cent increase in cyber attacks globally throughout the current conflict. CPR shared cyber attack data for NATO countries, regions.

Shykevich added that CPR’s findings reveal a clear trend, that collateral around the war between Russia and Ukraine has become a lure of choice for threat groups worldwide.

It is my strong belief that these campaigns are designed with the core motivation of cyber espionage.

I strongly recommend governments, banks and energy companies to reiterate cyber awareness and education to employees, and to implement cyber security solutions that protect the network on all levels, Shykevich said.

[Related: Vulnerability intelligence report reveals 136% increase in widely exploited security flaws]

cyber daily subscribe
Be the first to hear the latest developments in the cyber industry.