The breakdown of Shuckworm's continued cyber attacks against Ukraine. [Research Saturday]

Published: March 26, 2022, 7 a.m.

Guest Dick O'Brien from Symantec joins Dave Bittner on this episode to discuss how "Shuckworm Continues Cyber-Espionage Attacks Against Ukraine." The Russia-linked Shuckworm group (aka Gamaredon, Armageddon) has been active since 2013 and is known to use phishing emails to distribute either freely available remote access tools.\nIn July 2021, Symantec observed Shuckworm activity on an organization in Ukraine and this continued until August 2021. According to a\xa0November 2021 report\xa0from the Security Service of Ukraine (SSU), since 2014 the Shuckworm group has been responsible for over 5,000 attacks against more than 1,500 Ukrainian government systems. Dick walks us through Symantec's investigation.\nThe research can be found here:\nShuckworm Continues Cyber-Espionage Attacks Against Ukraine\n\nLearn more about your ad choices. Visit megaphone.fm/adchoices