Researchers from Secureworks’ Counter Threat Unit (CTU) are tracking phishing domains used by the “MOONSCAPE” threat actor to target users in Ukraine. The researchers note that Ukraine’s Computer Emergency Response Team (CERT-UA) has attributed this campaign to the Belarusian threat actor UNC1151, but Secureworks hasn’t yet confirmed this attribution. Belarus is one of Russia’s closest allies, and is assisting in Moscow’s war against Ukraine.
originally published onhttps://blog.knowbe4.com/domains-associated-with-phishing-directed-against-ukraine