
The Ukraine Computer Emergency Response Team (CERT-UA) has warned of cyberattacks targeting state institutions in the country as part of an espionage campaign.
This intrusion set comes from an actor tracked by authorities as UAC-0063 since 2021, which leverages phishing scams to deploy a variety of malicious tools onto infected systems. The Hacking Team’s origins are currently unknown.
In the attack chain described by the agency, the emails targeted unspecified ministries and purported to be from the Tajikistan embassy in Ukraine. The message is suspected to have originated from a previously compromised mailbox.
The email has a Microsoft Word document attached, and when macros are enabled, it launches an encoded VBScript called HATVIBE, which is used to drop additional malware.
These include keyloggers (LOGPIE), Python-based backdoors (CHERRYSPY) that can execute commands sent by remote servers, and tools focused on extracting files with specific extensions (STILLARCH or DownEx). included.
It is worth noting that Bitdefender recently documented DownEx being used by unknown actors in highly targeted attacks against government entities in Kazakhstan and Afghanistan.
“Further investigation of infrastructure and related files revealed that the group’s interests included Mongolia, Kazakhstan, Kyrgyzstan, Israel, [and] India,” CERT-UA said.
The findings show that some attackers are still using macro-based malware, even though Microsoft has disabled the functionality of Office files downloaded from the web by default.
That said, Microsoft’s restrictions have allowed some threat actors to experiment with attack chains and payload delivery mechanisms, including uncommon file types (CHM, ISO, LNK, VHD, XLL, WSF) and HTML smuggling. It is adapted to incorporate techniques.
Zero Trust + Deception: Learn How to Outsmart Attackers!
See how Deception can detect advanced threats, stop lateral movement, and strengthen your Zero Trust strategy. Join us for an insightful webinar!
Reserve your seat!
Enterprise security firm Proofpoint announced that from December 2022 onwards, multiple Initial Access Brokers (IABs) — actors who gain access to key targets and sell that access to other cybercriminals for profit — will use PDFs and He announced that he had observed that he was using OneNote files.
“The experimentation and regular migration of new payload delivery techniques by tracked threat actors, particularly the IAB, is markedly different from attack chains observed prior to 2022 and ushers in a new normal for threat activity.” said the company.
“The most experienced cybercriminals no longer rely on one or a few techniques, but frequently develop and iterate new TTPs. It suggests that they understand the time, capabilities and threat landscape” to rapidly develop and implement new technologies. ”