Lyce · Hybrid Watch

hw_641784d66fa04f85

Campagna UAC-0184 contro entità ucraine in Finlandia

Nel febbraio 2024, Morphisec ha segnalato una campagna informatica dell'attore di minaccia UAC-0184 che prendeva di mira entità ucraine, tra cui organizzazioni affiliate all'Ucraina operanti in Finlandia. Gli attacchi coinvolgevano l'IDAT Loader, che distribuiva il Remcos Remote Access Trojan (RAT), un malware in grado di controllare da remoto i computer infetti e rubare informazioni. La campagna utilizzava e-mail di phishing e sofisticate tecniche di elusione delle difese, in particolare la steganografia, in cui il codice malevolo era nascosto all'interno di un file immagine ed estratto durante il processo di infezione. Morphisec ha rilevato e prevenuto molteplici attacchi nelle prime settimane di gennaio 2024, prima che una minaccia correlata fosse documentata pubblicamente dal CERT-UA dell'Ucraina. I ricercatori hanno anche identificato tecniche come l'iniezione di codice e il “module stomping” per nascondere il malware, osservando che le identità esatte delle entità ucraine prese di mira non potevano essere divulgate.

Evento
2024-02-26
Pubblicazione
2024-02-26T16:35:29Z
Prima osservazione
2026-09-30T16:30:48.138Z
Stato revisione
Non valutato
Paesi
FI
Aggiornato
2026-10-02T16:30:09.889Z

Punteggi E/M/R/S

  • EEsistenza0/4 · Non valutato
  • MIntento0/4 · Non valutato
  • RLegame con attore russo0/4 · Non valutato
  • SResponsabilità dello Stato russo0/4 · Non valutato

Fatti

Nessun fatto

Fonti

  1. Ruolo
    discovery_lead
    Data
    2024-02-26T16:35:29Z

    In February 2024, Morphisec reported on a cyber campaign by the threat actor UAC-0184 targeting Ukrainian entities, including organizations affiliated with Ukraine operating in Finland. The attacks involved the IDAT Loader, which delivered the Remcos Remote Access Trojan (RAT), a malware capable of remotely controlling infected computers and stealing information. The campaign used phishing emails and sophisticated defense-evasion techniques, notably steganography, in which malicious code was hidden inside an image file and extracted during the infection process. Morphisec detected and prevented multiple attacks in the first weeks of January 2024, before a related threat was publicly documented by Ukraine’s CERT-UA. The researchers also identified techniques such as code injection and “module stomping” to conceal the malware, while noting that the exact identities of the targeted Ukrainian entities could not be disclosed.