Skip to main content

Threats Affecting Moldova

View all threats affecting or targeting Moldova. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Country:MoldovaMoldova

Threats Affecting Moldova

Click on any threat for detailed analysis and mitigation recommendations

A Russian APT group has been conducting targeted phishing campaigns against government entities in the Baltic and Balkan regions since at least 2023. The attackers use spoofed email attachments mimicking official documents to trick victims into submitting credentials on sophisticated fake login pages. These phishing pages feature blurred backgrounds and complex password validation, yet stolen credentials are exfiltrated regardless of password strength. The campaign specifically targets countries including Moldova, Ukraine, Lithuania, Bosnia and Herzegovina, Macedonia, Montenegro, Spain, and Bulgaria. The stolen credentials are sent to third-party services, enabling potential unauthorized access to sensitive government systems. This ongoing campaign poses a medium-level threat due to its targeted nature and potential for credential theft leading to further compromise. Defenders should focus on phishing awareness, email filtering, and credential monitoring to mitigate risks. The threat is particularly relevant to European government organizations in the affected regions due to geopolitical tensions and strategic importance.

Join the discussion

CopyCop, a Russian covert influence network, has significantly expanded its operations since March 2025, creating over 300 new fictional media websites targeting various countries. The network, likely operated by John Mark Dougan with support from Russian entities, aims to undermine support for Ukraine and exacerbate political fragmentation in Western countries. CopyCop's tactics include using deepfakes, AI-generated content, and impersonating media outlets to spread pro-Russian narratives. The network has widened its target languages and geographical scope, now including Turkey, Ukraine, Swahili-speaking regions, Moldova, Canada, and Armenia. While its core objectives remain unchanged, CopyCop has made marginal improvements to increase its reach, resilience, and credibility, including the use of self-hosted large language models for content generation.

Join the discussion

Multiple Russia-linked influence operations are targeting Moldova's September 2025 parliamentary elections, aiming to destabilize the process and impede Moldova's EU accession. These operations, including Operation Overload, Operation Undercut, Foundation to Battle Injustice, and Portal Kombat, are projecting negative views of President Maia Sandu and the ruling Party of Action and Solidarity. They portray EU integration as disastrous for Moldova's economy and sovereignty, while suggesting closer ties with Russia as a favorable alternative. The operations employ various tactics, including inauthentic news content, social media manipulation, and automated content generation. While their impact on voter behavior appears limited so far, they pose risks to media integrity and public trust.

Join the discussion

Bitdefender Labs has uncovered a new threat actor group named Curly COMrades, operating since mid-2024 to support Russian interests. The group targets critical organizations in countries experiencing geopolitical shifts, focusing on judicial and government bodies in Georgia and an energy distribution company in Moldova. Their primary objective is to maintain long-term network access and steal credentials. The attackers use proxy tools like Resocks, SSH, and Stunnel to establish multiple entry points, and deploy a new backdoor called MucorAgent. They also utilize compromised legitimate websites as traffic relays to complicate detection. The group's tactics include credential theft, lateral movement, and data exfiltration, employing both custom and open-source tools.

Join the discussion

New PathWiper Malware Strikes Ukraine's Critical Infrastructure Source: https://hackread.com/pathwiper-malware-hit-ukraines-critical-infrastructure/

Join the discussion

Silent Werewolf has launched two new campaigns targeting Russian and Moldovan organizations, utilizing sophisticated loaders to deliver malicious payloads. The attacks employ phishing emails with ZIP attachments containing obfuscated C# loaders. These loaders use legitimate tools and code obfuscation to evade detection. The first campaign exclusively targeted Russian energy, aircraft, and engineering sectors, while the second focused on both Moldovan and Russian entities. The adversaries hinder payload retrieval, making analysis challenging. They also utilize the Llama 2 large language model in some instances to bypass defenses. The campaigns demonstrate the threat actor's evolving tactics and their continued focus on espionage in the region.

Join the discussion
CVE-2024-56116: n/aCVE-2024-56116
0

A Cross-Site Request Forgery vulnerability in Amiro.CMS before 7.8.4 allows remote attackers to create an administrator account.

Join the discussion
CVE-2024-56115: n/aCVE-2024-56115
0

A vulnerability in Amiro.CMS before 7.8.4 exists due to the failure to take measures to neutralize special elements. It allows remote attackers to conduct a Cross-Site Scripting (XSS) attack.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Country: Moldova
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses