FRwL destroys data with Somnia to disrupt operations in Ukraine

Amber | Vulnerability Report

FRwL(From Russia with Love) group, tracked as UAC-0118 uses a fake website to trick Ukrainian organization employees into downloading the Advanced IP Scanner software. Upon installation, the system is infected with the Vidar stealer, which intercepts Telegram session data and takes control of the victim’s account.

Reduce real exposure. Not just vulnerability volume.