Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Supply Chain Attack Compromises Themes via Poisoned API Response
August 10, 2026
Anthropic Claude Opus 5 Reduces Indirect Prompt Injection Attacks to 2%
August 10, 2026
OpenClaw AI Agent Exploits Gym API to Steal Workout Slot
August 10, 2026
Home/Threats/Russian Threat Groups Exploit RDP, VPN, Supply Chain for Initial Access
Threats

Russian Threat Groups Exploit RDP, VPN, Supply Chain for Initial Access

Key Takeaways Russian state-sponsored threat groups significantly increased their cyber operations in 2025, with a 37.4% rise in incidents compared to the previous year. Initial access methods...

Emy Elsamnoudy
Emy Elsamnoudy
May 22, 2026 5 Min Read
77 0

Key Takeaways

  • Russian state-sponsored threat groups significantly increased their cyber operations in 2025, with a 37.4% rise in incidents compared to the previous year.
  • Initial access methods predominantly involved exploiting Remote Desktop Protocol (RDP) and Virtual Private Networks (VPNs), alongside sophisticated supply chain attacks and social engineering.
  • Targets included critical sectors such as government, defense, and energy infrastructure, primarily in Ukraine and across Europe.
  • The attacks often led to the deployment of destructive wiper malware, ransomware, and long-term espionage tools.
  • Organizations are urged to implement robust security measures, including MFA, Zero Trust, patch management, and employee training, to counter these evolving threats.

Russian state-sponsored cyber adversaries dramatically intensified their campaigns in 2025, leveraging a diverse and sophisticated arsenal of tactics to gain initial footholds within target networks. A recent report highlights that these methods frequently centered on exploiting vulnerabilities in Remote Desktop Protocol (RDP) and Virtual Private Networks (VPNs), executing complex supply chain compromises, and deploying highly tailored social engineering operations.

Table Of Content

  • Key Takeaways
  • RDP, VPN, and Supply Chain as Entry Points
  • Social Engineering and Phishing Campaigns
  • What You Should Do
  • Indicators of Compromise (IoCs):-

From weaponizing remote access tools and network gateways to subverting trusted software delivery mechanisms and manipulating personnel through deceptive campaigns, these threat actors have cultivated a formidable and adaptable toolkit for penetrating their targets. The findings are detailed in a comprehensive report obtained by Cyber Security News (CSN).

These are not opportunistic attacks but meticulously planned, persistent campaigns targeting governmental entities, defense contractors, energy infrastructure, and other critical sectors, with a particular focus on Ukraine and broader Europe. Noteworthy groups such as UAC-0002 (Sandworm), UAC-0001 (APT28), UAC-0010 (Gamaredon), and UAC-0190 (Void Blizzard) were all actively involved throughout the year.

Analysts from the National Security and Defense Council of Ukraine confirmed a substantial increase in both the volume and sophistication of these attacks in 2025. CERT-UA documented approximately 5,927 cyber incidents, representing a 37.4% surge compared to 2024. The report identifies RDP exploitation, VPN vulnerabilities, and phishing attempts across platforms like Signal, WhatsApp, and Telegram as primary methods for establishing initial network access.

The ramifications of these intrusions extended beyond simple data exfiltration. Numerous breaches resulted in the deployment of destructive wiper malware, ransomware variants, and persistent espionage tools engineered for covert data collection and exfiltration. This extensive activity underscores that these groups function not merely as cybercriminals but as integral components of a broader geopolitical strategy.

In certain instances, attackers streamlined their operations by acquiring stolen credentials from darknet forums, allowing them to bypass traditional phishing and move directly into target environments. This approach significantly reduced the window between initial access and active exploitation.

RDP, VPN, and Supply Chain as Entry Points

Remote Desktop Protocol remained a highly favored entry vector throughout 2025. Groups like UAC-0238 exploited exposed RDP services to deploy ransomware variants such as X2anylock, Warlock, and LockBit 3.0 within compromised systems.

VPN appliances were also heavily targeted, with vulnerabilities including CVE-2025-20333 and CVE-2025-20362 providing attackers with direct conduits into internal networks.

Supply chain attacks introduced another critical layer of risk. Adversaries focused on compromising software update mechanisms, third-party tools, and IT service providers to embed backdoors in environments where security scrutiny might be lower. Once inside, groups deployed malware families such as Remcos RAT, DarkCrystal RAT, XWorm, and Lumma Stealer to maintain persistent access.

Widespread vulnerabilities in platforms like Roundcube (CVE-2024-42009, CVE-2025-49113), Fortinet appliances (CVE-2024-55591, CVE-2024-21762), and archiving utilities like WinRAR and 7-Zip were actively exploited. Furthermore, older Microsoft Office flaws (CVE-2017-11882, CVE-2017-0199) continued to be leveraged, demonstrating that unpatched legacy vulnerabilities still pose significant risks.

Malicious payloads were delivered through various file types, including SVG, PNG, LNK, JS, and HTA files. These were frequently hosted on legitimate services such as Dropbox, Google Drive, and Cloudflare Tunnels to evade conventional network defenses. Attackers also employed “Living off the Land” techniques, utilizing built-in system tools like PowerShell, certutil, mshta.exe, and rundll32 to blend into normal system activity and avoid detection.

Social Engineering and Phishing Campaigns

Social engineering remained a consistently effective method for Russian threat groups to achieve initial access in 2025. Phishing lures were distributed via email platforms, including Microsoft O365, Roundcube, and Zimbra, as well as popular messaging applications like Signal, WhatsApp, and Telegram.

Attackers employed various deceptive techniques, such as ClickFix, fake CAPTCHA prompts, and PowerShell-based execution tricks, to deliver malware without triggering immediate security alerts. OAuth phishing, Device Code phishing targeting Microsoft Teams, and App-Specific Password phishing against Google accounts were observed, impacting over a thousand individuals.

Novel methods included QR-code session hijacking, dubbed GhostPairing, and the distribution of malicious Android APK files outside the Google Play store to infect devices with spyware like CamelSpy.

What You Should Do

  • Enforce Multi-Factor Authentication (MFA): Implement MFA across all services and applications, especially for remote access and critical systems.
  • Adopt Zero Trust Architecture: Move towards a Zero Trust model, verifying every user and device before granting access, regardless of location.
  • Implement Protective DNS: Utilize Protective DNS services to block access to known malicious domains and C2 infrastructure.
  • Prioritize Patch Management: Regularly apply security patches and updates for all software and hardware, addressing both new and legacy vulnerabilities, particularly for RDP, VPNs, webmail, and productivity suites.
  • Restrict RDP Access: Limit RDP access to only essential personnel and implement strong access controls, including VPN requirements and IP whitelisting.
  • Monitor for Unusual Activity: Deploy robust Endpoint Detection and Response (EDR) and Security Information and Event Management (SIEM) solutions to monitor for unusual use of built-in system tools (e.g., PowerShell, certutil) and suspicious network connections.
  • Conduct Regular Security Awareness Training: Educate employees on identifying and reporting social engineering attempts, phishing emails, and suspicious messages across all communication platforms.
  • Secure the Supply Chain: Vet third-party vendors and software thoroughly, implement strong software integrity checks, and monitor for unauthorized modifications in software updates.
  • Review and Audit Access: Regularly audit user accounts, permissions, and network configurations to ensure least privilege principles are maintained.

Indicators of Compromise (IoCs):-

Type Indicator Description
CVE CVE-2025-20333 Cisco ASA/AnyConnect VPN vulnerability used for initial access
CVE CVE-2025-20362 Cisco ASA/AnyConnect VPN vulnerability used for initial access
CVE CVE-2024-42009 Roundcube webmail vulnerability exploited by Russian APT groups
CVE CVE-2024-37383 Roundcube webmail vulnerability exploited in campaigns
CVE CVE-2025-49113 Roundcube webmail vulnerability used in 2025 campaigns
CVE CVE-2025-48700 Roundcube webmail vulnerability exploited in 2025
CVE CVE-2024-55591 Fortinet appliance vulnerability exploited for initial access
CVE CVE-2024-21762 Fortinet appliance vulnerability exploited for initial access
CVE CVE-2025-24472 Fortinet appliance vulnerability exploited for initial access
CVE CVE-2017-11882 Legacy Microsoft Office flaw still actively exploited
CVE CVE-2017-0199 Legacy Microsoft Office flaw still actively exploited
CVE CVE-2025-6218 WinRAR vulnerability used by Gamaredon/Sandworm/RomCom
CVE CVE-2025-8088 WinRAR vulnerability used by UAC-0180 (RomCom)
CVE CVE-2025-0411 7-Zip vulnerability exploited by UAC-0006
CVE CVE-2024-38213 Exploited by Sandworm (UAC-0212)
CVE CVE-2025-43300 Apple iOS/macOS vulnerability
CVE CVE-2025-49844 Redis vulnerability (1010 instances targeted)
CVE CVE-2025-49090 Matrix platform vulnerability
CVE CVE-2025-54315 Matrix platform vulnerability
Malware Remcos RAT Remote access trojan used for persistent access
Malware DarkCrystal RAT Remote access trojan deployed post-compromise
Malware XWorm Malware used in multiple Russian-linked campaigns
Malware Lumma Stealer Credential and data stealer deployed by multiple groups
Malware LameHug Malware used by UAC-0001 (APT28)
Malware HomeSteel Data exfiltration tool targeting Ukrainian organizations
Malware WreckSteel Destructive/exfiltration malware in 2025 campaigns
Malware FileMess Malware used in Ukrainian-targeted campaigns
Malware GiftedCrook Stealer targeting VPN credentials and Telegram data
Malware CamelSpy Android spyware distributed via fake APKs
Malware ZEROLOT Wiper malware linked to Sandworm
Malware PathWiper Wiper malware targeting Ukrainian organizations
Malware Sting Malware deployed by Sandworm in 2025
Malware Snake Keylogger Keylogger deployed in phishing-based campaigns
Malware PicassoLoader Loader used by UAC-0057 (Ghostwriter)
Malware SmokeLoader Loader malware used in multiple campaigns
Malware NetSupport RAT Legitimate RMM tool abused as malware
Malware Pterodo Backdoor associated with UAC-0010 (Gamaredon)
Malware AgentTesla Credential-stealing malware used in phishing campaigns
Malware FormBook Infostealer deployed via phishing
Malware Rhadamanthys Stealer malware distributed in 2025 campaigns
Malware RedLine Credential stealer observed in 2025 campaigns
Malware LokiBot Infostealer deployed via legacy Office exploit chains
Malware X2anylock Ransomware variant pushed via RDP exploitation
Malware Warlock Ransomware variant used by UAC-0238
Technique GhostPairing QR-code based account hijacking technique
Technique ClickFix Social engineering trick used to execute malicious scripts
Technique Device Code Phishing OAuth/device code abuse targeting Microsoft 365
Tool Cloudflare Tunnels Abused for C2 communication and payload hosting
Tool Telegram Used as C2 channel by UAC-0010 and others
Tool Telegraph Used for IP-based C2 routing by UAC-0010

Note: IP addresses and domains are intentionally defanged (e.g., [.]) to prevent accidental resolution or hyperlinking. Re-fang only within controlled threat intelligence platforms such as MISP, VirusTotal, or your SIEM.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

BreachCVEExploitMalwarePatchphishingransomwareSecurityThreatVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical FreePBX Flaw Lets Attackers Maintain Access with Six Persistence Layers

Next Post

Critical art-template npm Package Flaw Lets Attackers Backdoor Websites

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Cisco IOS XE Zero-Day Exploited, OWASP Top 10 for LLM
August 9, 2026
CSS Bomb Attacks Steal Passwords via Malicious Emails
August 9, 2026
Levi Strauss Data Breach Exposes Customer and Employee Data
August 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us