A well-organized cyber-espionage group is infecting computers at selected targets in Ukraine, turning on their microphone to record nearby audio, stealing documents, and storing exfiltrated data inside Dropbox accounts, according to security firm CyberX, who recently came across the malware used in these attacks.
Researchers identified over 70 organizations targeted in these attacks, with most located in Ukraine, and especially in the self-declared separatist states of Donetsk and Luhansk, near the Russian border.
Geographical distribution of Bugdrop targets
The target list includes editors of Ukrainian newspapers, a scientific research institute; a company that designs remote monitoring systems for oil & gas pipeline infrastructures; an international organization that monitors human rights, counter-terrorism and cyberattacks on critical infrastructure in Ukraine; and an engineering company that designs electrical substations, gas distribution pipelines, and water supply plants; among many others….