{"id":5449,"date":"2025-07-18T10:00:29","date_gmt":"2025-07-18T10:00:29","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/07\/18\/ukraine-hackers-claimed-cyberattack-on-major-russian-drone-supplier\/"},"modified":"2025-07-18T10:00:29","modified_gmt":"2025-07-18T10:00:29","slug":"ukraine-hackers-claimed-cyberattack-on-major-russian-drone-supplier","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/07\/18\/ukraine-hackers-claimed-cyberattack-on-major-russian-drone-supplier\/","title":{"rendered":"Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier"},"content":{"rendered":"<p>    Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Last week, Ukraine\u2019s Main Intelligence Directorate (GUR) orchestrated a sophisticated cyberattack against Gaskar Integration, a leading Russian drone manufacturer.<\/p>\n<p>The operation began with reconnaissance of the company\u2019s public-facing infrastructure, where threat actors identified vulnerable remote desktop services and outdated VPN gateways.<\/p>\n<p>Leveraging a zero-day in a third-party web application firewall, the attackers gained initial foothold within the corporate network. Once inside, they deployed custom <a href=\"https:\/\/cybersecuritynews.com\/malware-analysis\/\" target=\"_blank\" rel=\"noreferrer noopener\">malware<\/a> that exploited Windows Management Instrumentation (WMI) to execute lateral movement and harvest credentials.<\/p>\n<p>Hromadske analysts <a href=\"https:\/\/hromadske.ua\/viyna\/248088-kiberfakhivtsi-hur-paralizuvaly-robotu-odnoho-z-naybilshykh-vyrobnykiv-bezpilotnykiv-u-rosiyi-dzerelo\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">noted<\/a> that the malicious payload incorporated a dual-stage loader written in C++ and PowerShell.<\/p>\n<p>The first stage established persistence via a malicious WMI subscription, while the second stage decrypted a reverse-shell implant in memory.<\/p>\n<p>Communications were tunneled over <a href=\"https:\/\/cybersecuritynews.com\/staying-on-top-of-tls-attacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">TLS<\/a> using forged certificates that mimicked the company\u2019s own public key infrastructure.<\/p>\n<p>The malware\u2019s command-and-control (C2) infrastructure was hosted on compromised industrial control system servers, further complicating attribution and takedown efforts.<\/p>\n<p>By the time defenders detected anomalous network traffic, the attackers had exfiltrated more than 47 TB of technical data, including drone design schematics, production logs, and employee records.<\/p>\n<p>All backup copies on the victim\u2019s servers were irreversibly deleted, effectively crippling Gaskar\u2019s manufacturing and accounting operations.<\/p>\n<p>Workers were locked out of production software and physical access systems, with only fire exits remaining functional.<\/p>\n<p>Hromadske researchers identified key modules of the implant by reverse-engineering its unpacker.<\/p>\n<h2 class=\"wp-block-heading\"><strong>Infection Mechanism<\/strong><\/h2>\n<p>The malware\u2019s infection mechanism hinged on the exploitation of a <a href=\"https:\/\/cybersecuritynews.com\/waf-bypass-using-burp-plugin\/\" target=\"_blank\" rel=\"noreferrer noopener\">WAF bypass<\/a>. After gaining access, the attackers uploaded a tiny dropper\u2014less than 15 KB\u2014that executed a Base64-encoded PowerShell one-liner.<\/p>\n<p>This script reached out to a hard-coded C2 domain, downloaded an encrypted <a href=\"https:\/\/cybersecuritynews.com\/new-net-multi-stage-loader-attacking-windows-systems\/\" target=\"_blank\" rel=\"noreferrer noopener\">payload<\/a>, and invoked it entirely in memory to evade disk-based detection.<\/p>\n<p>The persistent WMI event filter was crafted as follows:-<\/p>\n<pre class=\"wp-block-code\"><code>$filter = Set-WmiInstance -Namespace rootsubscription -Class __EventFilter `\n  -Arguments @{\n    Name = \"SysUpdateFilter\"\n    EventNameSpace = \"rootcimv2\"\n    QueryLanguage = \"WQL\"\n    Query = \"SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA 'Win32_LocalTime'\"\n  }\nSet-WmiInstance -Namespace rootsubscription -Class __FilterToConsumerBinding `\n  -Arguments @{\n    Filter = $filter\n    Consumer = $consumer\n  }<\/code><\/pre>\n<p>This ensures execution on every system clock tick, granting the implant high survivability even after reboot.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 90%,rgb(169,184,195) 100%)\"><strong>Boost detection, reduce alert fatigue, accelerate response; all with an interactive sandbox built for security teams -&gt;\u00a0<a href=\"https:\/\/any.run\/demo?utm_source=csn&amp;utm_medium=article&amp;utm_campaign=top3_ciso_challenges&amp;utm_content=demo_1&amp;utm_term=160725\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Try ANY.RUN Now<\/a><\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/ukraine-hackers-claimed-cyberattack\/\">Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Tushar Subhra Dutta<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/ukraine-hackers-claimed-cyberattack\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ukraine Hackers Claimed Cyberattack on Major Russian Drone Supplier Last week, Ukraine\u2019s Main Intelligence Directorate (GUR) orchestrated a sophisticated cyberattack against Gaskar Integration, a leading Russian drone manufacturer. The operation began with reconnaissance of the company\u2019s public-facing infrastructure, where threat actors identified vulnerable remote desktop services and outdated VPN gateways. Leveraging a zero-day in a [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,649],"tags":[130],"class_list":["post-5449","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-threats","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5449"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=5449"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/5449\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=5449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=5449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=5449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}