CERT-UA Alerts Ukrainian State Authorities of Remcos Software-Fueled Cyber Attacks

February 8, 2023Rabbi LakshmananThreat Intelligence / Cyber ​​Warfare

cyber attack

Ukraine’s Computer Emergency Response Team (CERT-UA) has issued a warning of a cyberattack against the country’s national authorities deploying legitimate remote access software named Remcos.

Large-scale phishing campaigns have been attributed to tracked threat actors. UAC-0050given the toolset used, the activity was likely motivated by espionage, the agency explained.

The fake email that initiates the infection sequence claims to be from Ukrainian telecom company Ukrtelecom and contains a decoy RAR archive. Of the two files present in the file, one is a password-protected RAR archive of over 600 MB and the other is a text file containing the password to open her RAR file.

Embedded in the second RAR archive is an executable file that leads to the installation of Remcos remote access software, giving the attacker full access to the compromised computer.

Short for remote control and monitoring software, Remcos is offered by Breaking Security for free or as a premium version between €58 and €945.

cyber attack

The Italian company calls it “a lightweight, fast and highly customizable remote administration tool with a wide range of features”.

The latest CERT-UA advisory states that Ukraine’s State Cyber ​​Protection Center (SCPC) has conducted targeted attacks against public institutions and critical information infrastructure by a Russian state-sponsored threat actor known as Gamaredon. It was served when I pointed my finger at

Did you find this article interesting?Please follow us twitter and LinkedIn to read more exclusive content we post.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *