Russian cyberattacks against Western companies supporting Ukraine are increasing in scope as threat actors exploit fake browser updates to spread advanced malware. A new analysis shows how state-sponsored attacks are merging with traditional cybercrime, creating an increasingly complex threat landscape even for Nordic organizations.
A Russian hacking group is exploiting fake browser upgrades to spread malware to countries supporting Ukraine, demonstrating how cybercrime has become borderless and how the same techniques are being used in both state-sponsored attacks and ransomware campaigns.
Russian cyberattacks has become one of the most significant cybersecurity threats to companies and organizations in Europe and the Nordics.
Hacker groups with ties to Russia are exploiting legitimate and often trusted websites to spread advanced malware to Western companies that cooperate with or provide aid to Ukraine. A recent analysis from the cybersecurity firm Arctic Wolf points out that parts of the Russian military intelligence service GRU are likely behind the attacks.
The analysis shows that the attacks are a new variant of the well-known SocGholish method. The attack is based on planting malicious code on websites where visitors are tricked into believing that their browser needs to be updated. When the user clicks on the update, the attackers are given the opportunity to take the next step in the attack chain. This means that even security-conscious users risk unknowingly initiating serious intrusions.
Exploiting fake updates is an established technique among cybercriminals. What is new in this case is that the attackers can be linked to Russia and that they are targeting specific organizations in the West that support Ukraine in various ways, says Petter Glenstrup, Nordic Director at Arctic Wolf.
The analysis describes an incident where an employee clicked on a fake browser update on an infected website. The pop-up appeared legitimate but activated malware that immediately gave the attackers access to the system. Shortly after, they attempted to install advanced malware from the Russian-backed RomCom group. The combination of RomCom and SocGholish has not been observed before.
RomCom's malicious code is only activated when it identifies a specific target. In this way, narrowly targeted attacks can be hidden within broad global campaigns. What may appear on the surface to be mass attacks are in practice attacks against carefully selected organizations with specific connections to Ukraine.
The incident that forms the basis of the analysis affected an American technology company that had previously collaborated with a city with close ties to Ukraine. The incident illustrates a clear trend in which Russian threat actors targets organizations that directly or indirectly work in support of Ukraine. This makes the threat highly relevant also for the Nordic region, where many companies, authorities and non-profit organizations have been providing active assistance since 2022.
Russian cyberattacks are changing the threat landscape in the Nordics
According to Petter Glenstrup This is a clear example of how today's cyber threats have no geographical boundaries. The same tools and approaches are used in both financially motivated cybercrime and state-sponsored attacks. The threat actors operate in a common market despite completely different objectives, which makes the threat landscape more complex and difficult to predict.
SocGholish is also strongly associated with ransomware. The hacking group behind the method, called TA569, acts as a digital middleman, reselling access to compromised systems to other cybercriminals or state-sponsored actors. Many attacks are launched opportunistically without immediate consequences but should always be seen as a warning sign of a potentially more serious breach.
Anyone who discovers a SocGholish breach should act as if they are in the early stages of a ransomware attack. Quick action can limit the spread and prevent the attack from escalating into a full-scale breach, according to Petter Glenstrup.
For many organizations, this development means that traditional security assumptions are no longer sufficient. When legitimate websites are used as a distribution channel for malware, the line between trusted and risky environments is blurred, placing greater demands on both technical protections and ongoing user education.
Tips How to protect yourself against fake updates
Arctic Wolf recommends several preventive measures to reduce the risk of SocGholish and similar attacks. Software updates should always be done through central and approved channels and never through browser pop-ups. Organizations should monitor clients for anomalous network behavior and automated script execution. It is also important to use modern solutions for endpoint protection which can detect and stop attempts to install hidden malware. Clear procedures for how update notifications should be handled and ongoing user training are crucial to reducing the risk of successful attacks.
The full analysis can be read at Arctic Wolf.











