Suspected Russian threat actors breached Ukrainian organizations by leveraging 'living-off-the-land' (LotL) techniques, primarily using legitimate administrative tools and minimal custom malware to evade detection and maintain persistence. The attacks, detailed by Symantec and Carbon Black, targeted a large business services company and a local government agency, with initial access achieved through webshells—most notably the Localolive webshell, previously associated with the Sandworm group. Attackers exploited unpatched vulnerabilities on public-facing servers to deploy these webshells, then used PowerShell backdoors and scheduled tasks to further their objectives, including data exfiltration and system reconnaissance.
The threat actors demonstrated advanced knowledge of Windows native tools, running commands to exclude certain directories from antivirus scans, dumping registry hives, and enumerating files and processes—potentially to target password managers like KeePass. The use of dual-use tools and LotL tactics allowed the attackers to remain undetected for extended periods, highlighting the sophistication and stealth of Russian-linked cyber operations against Ukrainian targets. While a direct attribution to Sandworm was not confirmed, the tactics and tools used align with previous campaigns attributed to Russian military intelligence.

TTPs, infrastructure, and targeting history in one profile.
3 events from the most recent confirmed update back to the earliest known activity.
On or before October 29, 2025, Symantec’s Threat Hunter Team and VMware Carbon Black publicly reported the intrusions against Ukrainian organizations. The researchers said the activity was likely Russian in origin, noted overlap with prior Sandworm reporting, but stopped short of confirming attribution.
In a separate summer 2025 intrusion, the same or related operators breached a Ukrainian local government entity for about a week. The activity involved reconnaissance, credential theft, persistence mechanisms, and use of dual-use tools with minimal malware.
During summer 2025, attackers assessed as likely Russian compromised a large Ukrainian business services company and maintained access for roughly two months. They exploited unpatched vulnerabilities, deployed web shells including Localolive, and relied heavily on living-off-the-land techniques and legitimate tools to evade detection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcescworld.com
Open sourcetherecord.media
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.