All actors

Operation Groundbait

Linked to Ukraine by one source.

Reports
7
Last reported
Known CVEs
1
Origin
Ukraine
ID
operation-groundbait
Sources
ETDA
Merge evidence
0 alias matches

Reports per quarter

  1. 2016 Q2: 4 reports
  2. 2016 Q3: no reports
  3. 2016 Q4: no reports
  4. 2017 Q1: 1 report
  5. 2017 Q2: no reports
  6. 2017 Q3: no reports
  7. 2017 Q4: no reports
  8. 2018 Q1: no reports
  9. 2018 Q2: no reports
  10. 2018 Q3: no reports
  11. 2018 Q4: no reports
  12. 2019 Q1: no reports
  13. 2019 Q2: no reports
  14. 2019 Q3: no reports
  15. 2019 Q4: no reports
  16. 2020 Q1: no reports
  17. 2020 Q2: no reports
  18. 2020 Q3: no reports
  19. 2020 Q4: no reports
  20. 2021 Q1: no reports
  21. 2021 Q2: no reports
  22. 2021 Q3: no reports
  23. 2021 Q4: no reports
  24. 2022 Q1: no reports
  25. 2022 Q2: no reports
  26. 2022 Q3: no reports
  27. 2022 Q4: no reports
  28. 2023 Q1: no reports
  29. 2023 Q2: 1 report
  30. 2023 Q3: 1 report
Dated reports, 2016 Q2 to 2023 Q3.

CVEs named in reports

KEV marks a CVE in CISA's Known Exploited Vulnerabilities Catalog, and “ransomware” marks one that the catalog records as used in ransomware campaigns.

Reports

  1. Operation Groundbait- Espionage in Ukrainian war zones

    date in the title fromORKL

  2. Operation Groundbait:Analysis of a surveillance toolkit

    Malpedia library date ESET fromORKL

  3. Operation Groundbait:Analysis of a surveillance toolkit

    date in the CCS '25 data ESET fromCCS '25 data

Newest first. Details opens the report in Explore.