Back to news

Researchers link malware found in a Ukrainian government system to a Russian threat actor

Cisco found credential-stealing malware and remote-access tools, but could not determine whether data was stolen or prove how the infection began.

Malware discovered in a government network

Cybersecurity researchers found Amatera information-stealing malware operating in the computer system of an unidentified Ukrainian government organisation. Cisco assessed with moderate confidence that a Russian threat actor was responsible. The investigation found tools capable of collecting sensitive information and providing remote access, including the ability to inspect files, transfer data and execute commands.

The researchers did not establish that information was actually stolen or that an attacker actively exercised the installed access. They also could not reconstruct the infection’s starting point. Those limits matter: the evidence supports describing a likely Russian-linked intrusion, not a confirmed theft of Ukrainian government data or a formally attributed state operation.

A suspicious verification file

Investigators found a malicious file disguised under the name “verification.google”. In a separate infection involving the same Amatera malware, compromised websites presented users with a fake CAPTCHA verification screen. The prompt instructed victims to open a computer window and paste text that executed malware instead of completing a genuine human-verification check.

Similarities between the two infections led Cisco to assess that the Ukrainian compromise may have begun through the same technique. It could not confirm that pathway or prove that the same group operated both incidents. The malware also deployed software associated with cryptocurrency and credential theft, including code capable of replacing copied wallet addresses with attacker-controlled destinations.

Why Ukrainian systems remain high-value targets

Ukraine’s Foreign Ministry has described Russian cyber activity as an industrial-scale ecosystem aimed at government bodies, critical infrastructure and strategic sectors. In July, a Ukrainian cyber-diplomacy statement warned that such operations seek long-term access to decision-making and information systems in Ukraine and elsewhere in Europe. That official assessment provides context but does not independently attribute this specific intrusion.

Ukraine has continued strengthening its incident-response framework. New rules adopted in 2026 define how national, sectoral and regional response teams exchange threat information and coordinate with CERT-UA. The framework is intended to make government and critical-infrastructure reporting faster and more consistent when malware or other suspicious activity is detected.

What remains unresolved

Further forensic evidence would be needed to identify the initial access route, determine what the intruders did after installation and establish whether information left the network. The moderate-confidence attribution and unconfirmed CAPTCHA pathway should remain clearly qualified. The case nevertheless illustrates how familiar web-verification prompts can be repurposed to compromise government users without exploiting a sophisticated software vulnerability.