BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
Threat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Russian APT Deploys New Ukraine-Targeting Malware as Law Enforcement Disrupts Global Cybercrime Operations

Russian APT Deploys New Ukraine-Targeting Malware as Law Enforcement Disrupts Global Cybercrime Operations

March 5, 2026Nation-State & APT2 min readmedium

Originally reported by Security Affairs, The Record

#russia#ukraine#apt#malware#law-enforcement#cybercrime#leakbase#prince-group
Share

TL;DR

Russian threat actors launched a new espionage campaign against Ukraine using two undocumented malware strains. Meanwhile, international law enforcement scored major wins with takedowns of the Leakbase cybercrime forum and indictments against 62 individuals tied to the Prince Group scam operation.

Why medium?

Russian APT campaign with new malware targeting Ukraine represents ongoing nation-state activity, while law enforcement takedowns of Leakbase and Prince Group indicate significant disruption to cybercrime infrastructure.

Russian APT Campaign Targets Ukraine with Novel Malware

Researchers have documented a suspected Russian espionage operation targeting Ukraine that employs two previously unknown malware families. The campaign represents continued digital aggression in the ongoing conflict, with threat actors developing custom toolsets specifically for intelligence collection operations against Ukrainian targets.

The new malware strains indicate Russian threat actors continue investing in operational security and tool development, adapting their capabilities to evade detection and maintain persistent access to high-value networks.

FBI and European Authorities Dismantle Leakbase Cybercrime Forum

The FBI coordinated with European law enforcement agencies to shut down Leakbase, a major cybercriminal marketplace where threat actors traded stolen credentials and software exploits. The operation represents a significant disruption to underground economy infrastructure that facilitated credential stuffing attacks and vulnerability exploitation.

Leakbase served as a critical hub for cybercriminals seeking compromised account data and exploit tools. The takedown removes a key resource for threat actors conducting account takeover campaigns and targeted intrusions.

62 Indicted in Taiwan Over Prince Group Cybercrime Operation

Taiwanese prosecutors indicted 62 individuals connected to the Prince Group, a cybercriminal organization specializing in online fraud schemes. The Taipei District Prosecutors Office launched their investigation following the U.S. indictment of Prince Group founder Chen Zhi on money laundering charges.

The coordinated international response highlights the global reach of modern cybercrime operations and the increasing cooperation between law enforcement agencies in pursuing transnational criminal networks.

Industry Focus: Automation vs. Orchestration in Vulnerability Remediation

Security teams continue struggling with extended Mean Time to Remediate (MTTR) metrics, with 2024 research indicating an average of 4.5 months to address critical vulnerabilities. Organizations are evaluating automation versus orchestration approaches to streamline remediation workflows and reduce exposure windows.

Effective remediation programs require balancing automated responses for routine vulnerabilities with orchestrated workflows for complex, business-critical systems that demand human oversight and coordination.

Sources

  • https://therecord.media/russian-ukraine-hackers-malware
  • https://therecord.media/leakbase-cybercrime-fbi-europe-takedown
  • https://therecord.media/62-indicted-taiwan-prince-group-scams
  • https://securityaffairs.com/188917/security/automate-or-orchestrate-implementing-a-streamlined-remediation-program-to-shorten-mttr.html

Originally reported by Security Affairs, The Record

Tags

#russia#ukraine#apt#malware#law-enforcement#cybercrime#leakbase#prince-group

Related Intelligence

  • Iranian APT Groups Intensify Cyber Operations Against U.S. and Middle East Infrastructure

    highMar 7, 2026
  • Nation-State Roundup: Iran-Nexus APT Targets Iraq Officials, Phobos Admin Pleads Guilty, Multi-Year Campaign Exposed

    highMar 6, 2026
  • AI Weaponization and Major Data Breaches Dominate Cybercrime Landscape

    highMar 2, 2026

Explore

  • Dashboard
  • Privacy Threats
  • Threat Actors
← Back to the feed

Previous Article

← Security Roundup: Certificate Abuse, Phishing Evolution, and Enterprise Defense Gaps

Next Article

Music CEO Builds Open-Source Conflict Intelligence Platform Using Global Sensor Data →