Russian hackers target NATO country’s oil refinery

December 21, 2022

According to new Unit42 research, a hacking group known as Gamaredon APT, which the Ukrainian government claims is a unit of Russian intelligence, attempted to compromise a large petroleum refining company based inside a NATO member earlier this year.

Unit 42 claims that on August 30, a failed attempt to compromise a large petroleum refining company within a NATO member nation was launched using numerous changes in their tactics, techniques, and procedures (TTPs). Immediately after the initial invasion, an individual who appears to be associated with Trident Ursa threatened to harm a cybersecurity researcher based in Ukraine.

Since the beginning of the invasion, Unit 42 researchers have discovered over 500 new domains and 200 malware samples associated with Gamaredon APT. It was also stated that the Gamaredon group used the fast flux DNS technique to increase the resilience of the infrastructure against law enforcement takedown and to perform hard denylisting of the IP addresses associated with it.

The Ukrainian assessment and the Unit 42 report both agree that the group heavily relies on phishing as a malware vector. It spreads by tricking users into opening attached HTML files, clicking on a seemingly harmless link, or opening a Word document.

When Unit 42 examined a phishing sample with a low detection rate on VirusTotal, it discovered that the Word attachment itself contained no malicious code. It instead downloaded a remote template containing a macro, which then executed malicious code.

The sources for this piece include an article in TheHackerNews.

Top Stories

Related Articles

February 5, 2026 A security researcher at Koi named Oren Yomtov has uncovered a widespread malware operation embedded inside an more...

February 4, 2026 More than three million Fortinet devices have been exposed to a critical authentication-bypass vulnerability that is being more...

February 4, 2026 A now-patched security flaw in Docker’s built-in AI assistant exposed users to the risk of remote code more...

January 28, 2026 A suspected credit card skimming attack on the Canada Computers online store may have quietly exposed customer more...

Jim Love

Jim is an author and podcast host with over 40 years in technology.

Share:
Facebook
Twitter
LinkedIn