Britain Gains Access to Ukraine’s ‘Goldmine’ of Battlefield AI Data




Ukraine has transferred Seized Crypto Assets worth more than 8.3 million USDT to the country's Asset Recovery and Management Agency (ARMA), marking the first time virtual assets have been placed under the agency's management following a court decision. The transfer follows an investigation led by the State Bureau of Investigation into an international hacking group accused of carrying out cyberattacks, extortion, and money laundering across Europe and the United States.
According to Ukrainian authorities, the transferred cryptocurrency is valued at more than 372 million hryvnias and represents a milestone in the country's efforts to manage digital assets linked to criminal investigations.
The State Bureau of Investigation said the transfer was completed as part of an ongoing criminal investigation conducted in cooperation with the DVB of the National Police and U.S. law enforcement agencies.
Investigators determined that the virtual assets were stored in crypto wallets controlled by a member of the organized hacking group. Following a court order, more than 8.3 million USDT was transferred to ARMA's official crypto wallet.
Authorities said this is the first practical case in Ukraine where seized digital assets have been transferred to ARMA for management, demonstrating the country's ability to handle new categories of assets within the legal system.
According to investigators, members of the international hacking group carried out large-scale cyberattacks against individuals and companies in Europe and the United States.
The investigation alleges the group stole confidential information, demanded ransom payments, and laundered criminal proceeds in Ukraine through the purchase of residential properties, vehicles, and other high-value assets.
Authorities estimate that the criminal group's activities caused losses exceeding $100 million.
As part of the pre-trial investigation, four members of the group, including its alleged organizer, were detained and placed in custody.
The investigation resulted in the cryptocurrency seizure and the confiscation of additional assets with a combined value exceeding $11.1 million.
According to the State Bureau of Investigation, the seized property includes residential buildings, apartments, vehicles, approximately $1 million in cash, and digital assets equivalent to more than $8.3 million.
The Office of the Prosecutor General is providing procedural oversight for the criminal proceedings.
The State Bureau of Investigation said that after converting the cryptocurrency into fiat currency, authorities plan to purchase military bonds.
According to the agency, the initiative is intended to support Ukraine's economy during martial law while ensuring that assets obtained through criminal activity are redirected for state purposes.
Officials described countering transnational cybercrime and ensuring effective mechanisms for the seizure and management of criminal assets as key priorities.
ARMA said receiving the cryptocurrency marks an important step in the evolution of Ukraine's asset management system.
The agency stated that the successful transfer reflects coordinated efforts between the State Bureau of Investigation and the Office of the Prosecutor General, enabling the execution of the court's decision and preserving the value of the seized assets.
ARMA added that it is continuing to develop mechanisms for managing all categories of seized property, including real estate, corporate rights, and virtual assets, to ensure their preservation in the interests of the state and society.
The agency said the case demonstrates that as cybercriminals increasingly use digital technologies to conceal illicit proceeds, authorities must also strengthen their ability to manage and preserve cryptocurrency and other digital assets seized during criminal investigations.

Image Source: Cyber Police Department, National Police of Ukraine[/caption]

Ukrainian cyber defenders reported a newly intensified cyber campaign that is targeting Ukraine’s healthcare system and local government agencies, with attackers deploying increasingly sophisticated malware and social engineering tactics.
In a fresh advisory, the CERT-UA said the activity—linked to a threat cluster tracked as UAC-0247—spiked between March and April 2026, with clinical hospitals, emergency services, and municipal bodies bearing the brunt of the attacks.
The campaign begins with phishing emails disguised as offers of humanitarian assistance—a tactic designed to exploit trust during wartime conditions. Victims are urged to click on links that appear legitimate, sometimes backed by convincingly crafted fake websites or compromised third-party resources.
Behind the scenes, however, the links trigger a multi-stage infection chain that ultimately gives attackers remote control over the victim’s system.
Once clicked, victims download an archive containing a malicious shortcut file. This file activates a built-in Windows tool to execute remote code, initiating a sequence that includes decoy documents to avoid suspicion.
The attack escalates quickly. Malicious executables are deployed via scheduled tasks, injecting code into legitimate system processes such as RuntimeBroker.exe to evade detection.
Recent campaigns show an evolution in sophistication, with attackers introducing multi-stage loaders and custom executable formats. Payloads are often encrypted and compressed, making analysis and detection more difficult.
At later stages, attackers deploy reverse shell tools—including variants resembling “RAVENSHELL”—to establish encrypted communication with command-and-control servers and execute remote commands.
To maintain long-term access, attackers install a custom backdoor known as AGINGFLY, a C#-based malware designed for full remote system control. The tool enables:
Unlike conventional malware, AGINGFLY dynamically retrieves and compiles its command logic from remote servers, making it more adaptable and harder to detect.
Complementing this is a PowerShell-based tool dubbed SILENTLOOP, which helps maintain persistence and retrieves command server addresses—sometimes even pulling them from Telegram channels.
Once inside a network, attackers move quickly to expand access. CERT-UA observed tools like CHROMELEVATOR being used to extract browser credentials, while ZAPIXDESK targets WhatsApp data.
The attackers also conduct internal reconnaissance using both custom scripts and publicly available tools such as RUSTSCAN. For stealthy movement across networks, tunneling tools like LIGOLO-NG and CHISEL are deployed.
In at least one case, attackers went further—embedding the XMRIG cryptocurrency miner inside a modified version of the legitimate WireGuard application, highlighting a secondary motive of financial gain.
The campaign isn’t limited to civilian infrastructure. CERT-UA noted an incident in March where individuals connected to Ukraine’s defense sector were targeted via the Signal platform.
Attackers distributed a trojanized version of software used by FPV drone operators, packaged as a seemingly legitimate update. In reality, the download triggered a DLL side-loading attack that installed the AGINGFLY backdoor.
CERT-UA recommends reducing exposure by restricting the execution of high-risk file types such as LNK, HTA, and JavaScript files. The agency also urges organizations to limit the use of native Windows tools like mshta.exe and PowerShell where possible, as these are frequently abused in attacks.