Google’s Threat Analysis Group said on Wednesday that it has seen evidence indicating a range of state-backed threat actors are using the recent invasion of Ukraine to steal credentials through malicious emails and links. In a blog post , Google’s Billy Leonard said a “growing number” of financially-motivated groups as well as government-backed actors from China, Iran, North Korea and Russia are using the war as a pretext for several different kinds of attacks. “For example, one actor is impersonating military personnel to extort money for rescuing relatives in Ukraine. TAG has also continued to observe multiple ransomware brokers continuing...