They fake websites and hide viruses in "updates": how hackers attack Ukrainians
A routine download can allow attackers to gain access to your device
Hackers are increasingly relying on deceiving Ukrainians: they copy familiar websites and pass off malicious files as ordinary documents or updates. According to the State Service for Special Communications and Information Protection, in the first half of 2026 over 88% of cyberattacks in Ukraine were related to malicious software, social engineering, infections, and system compromise. According to cip.gov.ua.
One method of deception is creating websites that outwardly resemble resources of well-known institutions. Attackers imitate pages of CERT-UA, the document management systems of the Verkhovna Rada and the Brave1 platform.
Visitors to such a fake page are offered to install a “security update” or a “service module.” However, the downloaded file may contain a program that gives hackers remote access to the device.
To disguise their actions, perpetrators also use legitimate online services. Archives with malicious content are hosted on well-known file-sharing sites and GitHub, and stolen data is transmitted using Telegram bots. The State Service for Special Communications and Information Protection explains: such attacks are harder to detect because the hackers’ actions can resemble normal use of Internet services.
In the distribution of cyberattacks provided by the agency, the largest shares were malicious software and social engineering:
- malicious software — 33%;
- social engineering — 31%;
- infection incidents — 15%;
- system compromise — 4.5%.
Fake login pages and forged software update notifications are also used by the Russian hacker group Midnight Blizzard. Through hotel Wi-Fi networks it steals users’ data and infects their devices with malicious software.
Previously we wrote:





