In the first half of 2026, more than 88% of all cyberattacks in Ukraine were linked to malware (33%), social engineering (31%), infection (15%) and system compromise (4.5%).
This was reported by the State Service of Special Communications and Information Protection.
The report notes that attackers are increasingly relying not so much on technical sophistication as on deception and users’ trust, according to the Cyber Threats: Ukraine report.
One of the most common tactics has been the use of a plausible cover. Groups create fake web pages that imitate resources belonging to the CERT-UA team itself, the Verkhovna Rada of Ukraine’s document management system, or the Brave1 platform. Users are invited to download what is supposedly a "security update" or a "service module", which in fact is a tool for remote access to the device.
In addition, hackers are actively hiding their malicious payload on legitimate platforms. Instead of creating their own suspicious websites, they upload archives containing viruses to well-known file-sharing services and GitHub, and transmit stolen data via Telegram bots.
"This tactic makes attackers’ network traffic resemble ordinary user activity, significantly complicating the work of cyber defence systems," the statement says.
- Earlier, the Security Service of Ukraine also reported that Russians are creating fake pages for government bodies in Ukraine and the media. The SBU’s Cybersecurity Department has already identified and blocked more than 50 resources whose appearance copied the Security Service’s branding.