Multiple Ukrainian news websites and the Institute of Mass Information have received phishing emails mimicking invitations to an online conference. The attackers were attempting to establish correspondence in order to prompt the targets to fill out a registration form, thus sharing their email login data.

One such email arrived in the inbox of Oleh Dereniuha, director of the Mykolaiv-based news website MykVisti, on 11 August. The sender, signed as Oksana Moroz, claimed to have processed his application for a conference and asked him to confirm he would be able to attend. The team had not submitted any such application.

Dereniuha asked a follow-up question and received one more email referring to a conference titled “Tactical Medicine and the Evacuation of the Wounded in Combat Situations.” He was invited to follow a link, log into an account, and receive a PDF document containing a personal password and participant details.

However, hovering the cursor over the link listed in the letter showed a different address — a third-party domain unrelated to the website name displayed to the recipient.

Dereniuha says that this scheme is designed in such a way that once the target has replied to the first email, they no longer see the next message as spam but as a continuation of ordinary correspondence.

“Phishing is evolving, too. The person replies themselves, a conversation begins, so the next message no longer looks like spam from a bot but as the continuation of a normal exchange. And it doesn’t look as crude as when the phishing link is included in the first email straight away,” he noted.

The link in the email was disguised to look like the website medecine.ua, but in reality, following a series of redirects, it led to a third-party domain mimicking the interface of the email service Ukr.net.

“This is a classic scheme for accessing one’s email. And VirusTotal and similar services don’t flag this link as malicious yet. So arguments such as ‘I ran it through a scanner, it came back clean, I can click the link’ are no longer reliable,” Oleh Dereniuha explained.

The Institute of Mass Information received a similar email on 11 August. The message came from [email protected], signed “Ulyana Kurilets.” It thanked the recipient for their supposed interest in the conference and asked them to confirm they would be joining.

The email contained no specific information about the conference’s topic, organisers, or program. However, the sender said that participation details would be sent once a reply was received.

The Cherkasy-based news outlet 18000 received an identical email in its editorial inbox. The sender signed as Viktoriya Sviridenko and wrote from [email protected].

Digital Security Lab expert Maksym Lunochkin said in a comment to IMI that there was no evidence as yet that the phishing campaign was targeting media outlets specifically, and that its organisers had not been identified.

According to him, the attackers are using a common scheme involving an invitation to an online or in-person conference in order to later lure users into giving up their login data.

“We’re seeing yet another phishing campaign wherein the attackers use a similar scheme: they invite the target to join an event, an online or in-person conference, and wait for a reply from the target confirming they would participate. The next message then contains a link to a phishing page or malicious software,” Lunochkin explained.

He added that such messages can arrive through various communication channels such as email, Signal, WhatsApp, other messaging apps, and social media platforms. The attackers may impersonate real individuals or organisations.

The expert said that in the emails in question, the attackers were attempting to steal logins and passwords for Ukr.net accounts.

“If the target replies, they’re sent an email supposedly containing a registration link. In reality, though, the hyperlink hidden within the text leads to a phishing website that mimics the UKR.net login page,” the expert said.

Lunochkin stressed that there was no evidence yet to suggest that the campaign was purposefully targeting media outlets or newsrooms. No data pointing to the actors behind the campaign have been found.

This is not the first time that MykVisti team has received a phishing email mimicking invitations to events. In October 2025, a journalist with the publication received a message that appeared to be an invitation to a fictitious NATO–UAF event and contained a phishing link disguised as a registration form.

The Institute of Mass Information strongly advises journalists vet such letters even if they look unlike classic spam or mass mailing by malicious actors.