Cloudflare Chaos: Ukraine’s Military Targeted in Malware Mayhem
The Computer Emergency Response Team of Ukraine (CERT-UA) warns that the threat actor UAC-0125 is using Cloudflare Workers to trick military personnel into downloading malware disguised as the Army+ app. The malware grants remote access to attackers, who are linked to Russian APT groups. Phishing attacks via Cloudflare services have surged dramatically.

Key Points:
- UAC-0125 uses Cloudflare Workers to dupe Ukrainian military into downloading malware.
- The malware disguises itself as an app called Army+ and uses a script to establish remote access.
- UAC-0125 is linked to notorious APT group associated with Russia’s GRU.
- Phishing attacks using Cloudflare services have seen a significant rise.
- EU sanctions have been imposed on individuals and entities linked to Russian cyber activities.
Already a member? Log in here
