Ukraine’s Asset Recovery and Management Agency (ARMA) said its servers were hit by a cyberattack as the agency was preparing to appoint a manager for seized corporate rights in IDS Ukraine, a company tied to assets taken from sanctioned Russians. ARMA said it is investigating whether the intrusion was part of a broader coordinated effort to disrupt the agency’s work and interfere with the asset-management process, while Ukraine’s Security Service (SBU) has opened an investigation.
The agency also reported unauthorized access to an internal database containing information on ARMA officials. ARMA said the latest incident followed other interference attempts dating back to the spring, including a separate cyberespionage campaign in April that Ukrainian authorities attributed to APT28. Officials have not publicly named the actor behind the newest attack or released technical details about the intrusion.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
Ukraine's Security Service began investigating the cyberattack on ARMA. ARMA did not publicly identify an attacker or release technical details at the time.
ARMA said unauthorized access occurred to an internal database of ARMA officials. The agency was assessing whether this access and the cyberattack were part of a coordinated effort to undermine its operations.
On Tuesday, ARMA said its servers were targeted by a cyberattack while it was preparing to select a manager for seized corporate rights in IDS Ukraine. The agency said the competition would proceed as planned despite the incident.
In April, Ukrainian state officials said ARMA employees were targeted in a cyberespionage campaign attributed to APT28. ARMA's acting head said at the time that the hackers failed to penetrate the agency's internal systems.
Ukraine seized the corporate rights of Russian shareholders in IDS Ukraine after Russia's full-scale invasion. The seized assets later became part of ARMA's management and transfer process.
ARMA said it had detected signs of suspected unlawful interference in its work beginning in the spring. The agency later examined whether this interference was part of a coordinated effort to disrupt the IDS Ukraine asset-management competition.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcearma.gov.ua
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.