Wednesday, May 3, 2023

Russian hackers use WinRAR to wipe Ukraine state agency’s data

In a new advisory, the Ukrainian Government Computer Emergency Response Team (CERT-UA) says the Russian hackers used compromised VPN accounts that weren't protected with multi-factor authentication to access critical systems in Ukrainian state networks.

However, when WinRar is executed, the threat actors use the "-df" command-line option, which automatically deletes files as they are archived. The archives themselves were then deleted, effectively deleting the data on the device.

Publisher: BleepingComputer
Twitter: @BleepinComputer
Reference: (Read more) Visit Source



No comments:

Post a Comment