Bobik Malware Linked with Attacks in Ukraine

russia ukraine cyberattacks

Bobik is the name of a piece of malware acting like a remote access trojan. Security researchers have linked Bobik to a threat actor known for its pro-Russian attitudes, known by the alias NoName 057(16).

According to researchers, the NoName 057(16) threat actor would go on its Telegram account and post about its latest attacks at times that coincided with distributed denial of service (DDoS) attacks using Bobik.

Bobik has both spying tools and DDoS tools at its disposal. The malware can collect information on the compromised device, including keystroke logging. The malware can also be used to launch DDoS attacks using infected devices that have been added to its botnet.

Bobik's infection chain is associated with another piece of malware known as RedLine stealer. RedLine is used as a dropper, fetching Bobik, which in turn deploys its DDoS component.

The malware has been used in attacks both against government and military entities in Ukraine and against entities located in countries that support Ukraine. The latter include mobile carrier Verizon and British multinational parts supplier GKN Ltd.

Bobik has also been used in attacks against targets in Lithuania, Latvia and Poland, as well as Scandinavian countries.

September 9, 2022
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.