Tuesday, August 11, 2026
LIVEThe Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///The Unrelenting Cyber Battle: Hacking Threats and the Imperative of Robust Data Protection///Navigating the Cyber Labyrinth: Bolstering Defenses Against Evolving Hacking Threats///The Dual Front War: Battling Hacking and Bolstering Data Protection in the Digital Age///The Ever-Evolving Cyber Threat Landscape: Navigating Hacking and Fortifying Data Protection///The Unseen Battle: Fortifying Data in an Age of Relentless Hacking///The Unseen War: Hacking's Relentless Advance and the Imperative of Data Protection///The Evolving Threat Landscape: Hacking, Data Protection, and the Imperative for Proactive Security///Navigating the Digital Minefield: Bolstering Data Protection in an Era of Relentless Hacking///The Dual Fronts of Digital Defense: Combating Hacking and Fortifying Data Protection///Hacking's New Frontier: Fortifying Data Protection in the Age of Advanced Cyber Threats///The Dual Front: Navigating Hacking Threats and Fortifying Data Protection in the Digital Age///Navigating the Digital Gauntlet: The Evolving Nexus of Hacking and Data Protection///
Subscribe
Cyber Security
Independent · Digital
Thehackingpost
CybersecurityAI-assisted

Ukraine Hackers Attacking Russian Aerospace Companies and Other Defence-Related Sectors

Ukraine-linked hackers are stepping up cyberattacks against Russian aerospace and wider defence-related companies, using new custom malware to steal designs, schedules, and internal emails.

Ukraine-linked hackers are stepping up cyberattacks against Russian aerospace and wider defence-related companies, using new custom malware to steal designs, schedules, and internal emails.

The campaign targets both prime contractors and smaller suppliers, aiming to map production chains and expose weak points in Russia’s war industry. The tools used in this campaign are simple, but they are used with care and good planning.

Defaced homepage of KrasAvia’s website (Source – Intrinsec) The malware first appeared in late 2024 in spear-phishing waves sent to engineers and project managers working on avionics, guidance systems, and satellite links.

Lures used fake job offers , conference invites, and contract updates, with attached documents that exploited outdated office software on Windows hosts. Once opened, the file quietly dropped a small loader that set the stage for the main payload.

Intrinsec security analysts identified the malware after seeing repeated outbound traffic from a defence integrator’s remote office to rare command servers hosted on bulletproof infrastructure.

Their complete technical breakdown shows that the attackers carefully tuned each payload to the victim’s role, adding custom modules for email scraping, document theft, and credential capture.

The campaign targets both prime contractors and smaller suppliers, aiming to map production chains and expose weak points in Russia’s war industry.
Adam Foster · Thehackingpost

Content of the email (left), and the phishing page (right) (Source – Intrinsec) The operation hits research labs, testing ranges, and logistics firms that support aircraft, drones, and missile systems. Stolen data can reveal parts shortages, delivery delays, and software bugs, giving Ukrainian planners a clearer view of Russian combat readiness.

The infection chain is simple but smart. The first loader, often a small DLL , runs in memory only and pulls a second-stage script from a hard-coded URL.

That script injects the final payload into a trusted process such as explorer.exe, which helps it blend with normal user activity.

Intrinsec researchers noted that the payload uses a compact command loop to stay flexible. A typical routine, as seen in memory dumps, looks like this:-

Advertisement

while (connected) This simple logic lets the operator switch between silent data theft and hands-on keyboard control. Each stage is built to keep noise low on the host.

Despite its clear design, the malware avoids noisy persistence tricks, instead relying on scheduled tasks and hijacked update tools to return after reboots while staying hard to spot.

Follow us on  Google News ,  LinkedIn , and  X  to Get More Instant Updates ,  Set CSN as a Preferred Source in  Google .

Based on reporting by Cyber Security News.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories