Researchers and government defenders linked CredoMap, a .NET credential-stealing malware family, to Russian state actor APT28 in phishing campaigns targeting users and organizations in Ukraine during the Russia-Ukraine war. Google reported APT28 distributing the malware through Ukraine-themed lures in password-protected ZIP archives, while CERT-UA documented a malicious RTF file, "Nuclear Terrorism A Very Real Threat.rtf", that exploited CVE-2022-30190 (Follina) to fetch staged payloads from attacker-controlled or compromised infrastructure before launching the stealer. Broader reporting on wartime cyber activity also placed the operation alongside other Russian espionage and disruptive campaigns aimed at Ukrainian government, critical infrastructure, and regional defense targets.
Technical analysis showed CredoMap harvesting browser credentials and cookies from Google Chrome, Mozilla Firefox, and Microsoft Edge, including decryption of Chromium secrets via DPAPI and AES-GCM, then exfiltrating the data to a hard-coded command-and-control server at 162.241.216.236 over IMAP on port 143 using embedded credentials. CERT-UA said the infection chain retrieved article.html from frge.io and additional files including SQLite.Interop.dll and docx.exe from kompartpomiar.pl, which was assessed as likely compromised. After collection, the malware removed copied artifacts, deleted supporting files, and self-deleted, underscoring a focused espionage operation designed to steal access and browsing data while minimizing forensic traces.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
38 events from the most recent confirmed update back to the earliest known activity.
On June 20, 2022, CERT-UA reported an attack using the malicious RTF document "Nuclear Terrorism A Very Real Threat.rtf." Opening the file exploited CVE-2022-30190, downloaded article.html from frge[.]io, and fetched SQLite.Interop.dll and docx.exe, which CERT-UA linked to CredoMap and likely associated with APT28.
Google TAG said that on June 19, 2022 it disrupted a campaign involving more than 10,000 spam emails impersonating the State Tax Service of Ukraine. The ZIP attachment contained a malicious RTF file exploiting CVE-2022-30190.
CERT-UA assessed that distribution of the malicious RTF may have begun as early as 2022-06-10. The lure exploited CVE-2022-30190 to download article.html and ultimately run the CredoMap payload.
CERT-UA said the malicious document "Nuclear Terrorism A Very Real Threat.rtf" had metadata showing it was modified on 2022-06-09. This document was later used to exploit Follina and deliver CredoMap.
Google TAG reported that on May 24, 2022, the newly registered domain kompromatua.info was used to target the Academy of Ukrainian Press. The Dropbox-linked lure delivered a malicious Excel binary workbook that fetched a Cobalt Strike DLL.
On May 23, 2022, a phishing campaign targeted Ukrainian organizations in the technology, retail, and government sectors using a Microsoft-themed lure, according to Google TAG. The campaign delivered an IcedID binary named KB2533623.msi from microsoftua.com.
Google TAG reported that on May 19, 2022, UAC-0098 used support@starlinkua.info to impersonate Elon Musk and StarLink in phishing emails. The campaign delivered an MSI installer from starlinkua.info that dropped IcedID.
On May 17, 2022, UAC-0098 used a compromised hotel email account in India to send phishing emails with a ZIP archive containing a malicious XLL file. Google TAG said the same account also targeted humanitarian NGOs in Italy.
Google TAG reported that on May 11, 2022, UAC-0098 sent phishing emails to hospitality-sector organizations while impersonating the National Cyber Police of Ukraine. The campaign used the attacker-controlled domain cyberpolice.gov.uz.ua and fetched an IcedID DLL via PowerShell.
The OSINT review said CERT-UA reported on May 6, 2022 that UAC-0028 sent malicious emails impersonating CERT-UA with a password-protected RAR archive named UkrScanner.rar. The self-extracting archive deployed malware dubbed CredoMap.
On May 3, 2022, Google TAG reported that APT28 targeted users in Ukraine with a new .NET credential-stealing malware. The malware stole cookies and saved passwords from Chrome, Edge, and Firefox and exfiltrated the data via email to a compromised account.
Google TAG reported that on April 13, 2022, at least three malicious Excel attachments with mobilization-themed filenames were sent to Ukrainian organizations. The activity was linked to the UAC-0098 cluster.
The OSINT review said Microsoft obtained a court order on April 7, 2022 to seize seven domains used by Strontium for phishing attacks. Microsoft said the infrastructure had targeted Ukrainian media organizations and foreign-policy entities in the US and EU.
Google TAG said it began actively tracking UAC-0098 after identifying a late-April 2022 phishing campaign delivering AnchorMail via a builder it called LackeyBuilder. TAG linked this activity to earlier Ukraine-targeting phishing using mobilization-themed lures.
The OSINT review said CERT-UA reported on March 16, 2022 that UAC-0028 phished UkrNet accounts using tinyurl links embedded in QR codes. Victims were led to credential-harvesting sites hosted on *.frge[.]io and *.m.pipedream[.]net.
Lab52 analyzed a lure document named "Ukraine Conflict Update 16_0.doc" with a creation time of 2022-03-16. The malicious Office document used obfuscated VBA and PowerShell to download and execute a Quasar RAT variant.
The OSINT review said Google Threat Analysis Group disclosed on March 7, 2022 that FancyBear was running large credential-phishing campaigns targeting ukr[.]net users. The campaign used malicious blogspot links redirecting victims to credential-harvesting pages on *.frge[.]io.
On February 26, 2022, Ukrainian Vice Prime Minister Mykhailo Fedorov announced the creation of the crowdsourced IT Army. The initiative was intended to conduct offensive operations against Russian infrastructure.
Deep Instinct reported that the Conti ransomware group publicly announced support for the Russian government on February 25, 2022. The statement came amid the broader cyber conflict surrounding Russia’s invasion of Ukraine.
On February 25, 2022, a phishing campaign targeted Ukrainian troops’ private i.ua and meta.ua accounts, according to Deep Instinct. The report attributed the activity to UNC1151, also known as GhostWriter.
Deep Instinct reported that on February 24, 2022, the portal of Ukraine’s Ministry of Agrarian Policy and Food was defaced by a group calling itself Free Civilian. The group also offered databases containing sensitive government and citizen information for sale.
NVISO said ESET first detected IsaacWiper on February 24, 2022. The malware was used in destructive attacks against the Ukrainian government.
Deep Instinct reported that on February 23, 2022, the websites of Ukraine’s Ministry of Foreign Affairs and the Security Service of Ukraine were taken down. The same day, Ukrainian troops also received threatening SMS messages intended to demoralize them.
ESET discovered first instances of HermeticWiper around 4 p.m. CET on February 23, 2022, on several hundred machines in Ukraine. Deep Instinct also described Ukrainian organizations being targeted that day by the destructive wiper.
NVISO reported that on February 23, 2022, DDoS attacks impacted the websites of Ukraine’s Ministry of Defence, Ministry of Foreign Affairs, and other government institutions. SecurityScorecard later assessed the February 23 attack primarily used DNS amplification via the Zhadnost botnet.
A suspected APT29 EnvyScout sample was reported on February 18, 2022, according to the OSINT review. The campaign used HTML smuggling to deliver an ISO file in a COVID-19-themed lure reportedly aimed at the Turkish embassy.
On February 15, 2022, DDoS attacks affected Ukraine’s Ministry of Defence, the Armed Forces of Ukraine, and two national banks, disrupting internet banking for several hours. SecurityScorecard later analyzed this as a distinct attack using HTTPS flooding and roughly 200 source IPs.
NVISO reported that on February 8, 2022, Ukraine’s Security Service shut down a Russian trolling farm. Authorities said it had spread fake news and false bomb threats to create panic.
SecurityScorecard assessed that DDoS attacks on February 27-28, 2022 primarily used DNS amplification through a newly named botnet, Zhadnost. The attacks targeted Ukrainian government and financial websites and relied heavily on MikroTik routers with DNS recursion enabled.
An OSINT review cited Google Threat Analysis Group as reporting an ongoing FancyBear credential-phishing campaign focused on Ukraine. The infrastructure reportedly used *.eu3[.]biz, *.eu3[.]org, and blogspot[.]com hostnames.
Between January 13 and 14, 2022, more than 70 Ukrainian state websites were attacked in a coordinated defacement campaign, according to NVISO. Ukraine’s Security Service assessed the activity was enabled through a vulnerable content management system.
NVISO reported that WhisperGate began affecting several Ukrainian organizations on January 13, 2022. The malware wiped the master boot record and corrupted files while displaying a fake ransom note.
Deep Instinct said forensic analysis found a HermeticWiper variant with a timestamp dating to December 2021. This suggested the destructive operation had been prepared well before deployment in Ukraine.
Intezer reported that the phishing operation later expanded to target government entities in Georgia. VirusTotal uploads tied to Georgia-focused lures were observed on June 17 and July 5, 2021.
Intezer said Fortinet had previously reported in May 2021 on the early stages of an ongoing phishing campaign targeting the Ukrainian government. The campaign initially used the Saint Bot downloader before later evolving.
NVISO reported that ESET discovered CaddyWiper on March 14, 2022. It was identified as the fourth data-wiping malware used against Ukraine and had been deployed via Group Policy Objects.
On March 12, 2022, phishing emails impersonating the Ukrainian government delivered a fake antivirus update, according to NVISO. The campaign downloaded a Cobalt Strike beacon from a Discord CDN and also delivered a Go dropper plus the GraphSteel and GrimPlant backdoors.
NVISO said Zscaler reported on March 2, 2022 that a threat actor targeted Ukraine’s Ministry of Defense using DanaBot’s download-and-execute module. The activity formed part of the broader cyber operations against Ukraine.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
12 references tracked. Mallory keeps watching after this page renders.
securityscorecard.com
Open sourcesecurityscorecard.com
Open sourceintezer.com
Open sourceblog.bushidotoken.net
Open sourcelab52.io
Open sourcedeepinstinct.com
Open sourceblog.nviso.eu
Open sourcehub.dragos.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.