Game over — hackers are using a spoofed version of Minesweeper to snare victims
Russian hackers are targeting financial institutions in Europe and the United States with a nostalgia-laden gaming lure.
Two security agencies in Ukraine – CSIRT-NBU, and CERT-UA, hae warned of a new phishing campaign conducted by a threat actor they track as “UAC-0188”. This group is also known as “FRwL”, which is most likely an abbreviation of “From Russia with Love”, a 1963 James Bond film.
The group is sending phishing emails from “[email protected],” pretending to be a medical center. The emails come with the subject line “Personal Web Archive of Medical Documents,” and carry a 33 MB attachment, a .SCR file hosted on Dropbox containing code from a Python clone of the famous Minesweeper Windows game. However, the clone also downloads additional scripts from a remote source which, after a few more steps, end up installing SuperOps RMM.
Abusing SuperOps RMM
SuperOps RMM, short for Remote Monitoring and Management, is a software platform designed to assist managed service providers (MSPs) and IT professionals in managing and monitoring client IT infrastructure remotely. It integrates various tools and functionalities to streamline IT operations, enhance security, and improve efficiency.
The tool is legitimate, but often abused, similar to what happened to Cobalt Strike. SuperOps RMM grants the attackers remote access to the compromised systems, which they can then use to deploy more serious malware or infostealers, grabbing login credentials, sensitive data, banking information, and more.
IT admins should monitor their network activity for the presence of SuperOps RMM, and if they don’t usually use the software (or know not to have it installed at all), should treat the activity as a sign of compromise.
There was no word on who the usual targets are, or how many organizations the group managed to compromise.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
Via BleepingComputer
More from TechRadar Pro
Russian hackers are targeting financial institutions in Europe and the United States with a nostalgia-laden gaming lure. Two security agencies in Ukraine – CSIRT-NBU, and CERT-UA, hae warned of a new phishing campaign conducted by a threat actor they track as “UAC-0188”. This group is also known as “FRwL”, which…
Recent Posts
- 9 dog-care gadgets that are so clever they deserve a treat — including an ingenious on-the-go water solution and a ‘canine FitBit’
- Control Resonant is a sequel — and also a starting point
- Summer Game Fest Live 2026: The biggest news, trailers, and announcements
- OpenAI rolls out a Lockdown Mode for extra protection against prompt injection attacks
- The Dyson HushJet Mini Cool is the powerful personal fan you won’t want to live without this summer — and it’s surprisingly reasonably priced, too
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023