Lyce · Hybrid Watch

hw_641784d66fa04f85

Russia-linked UAC-0184 target Ukrainian entities in Finland with malicious software.

In February 2024, Morphisec reported on a cyber campaign by the threat actor UAC-0184 targeting Ukrainian entities, including organizations affiliated with Ukraine operating in Finland. The attacks involved the IDAT Loader, which delivered the Remcos Remote Access Trojan (RAT), a malware capable of remotely controlling infected computers and stealing information. The campaign used phishing emails and sophisticated defense-evasion techniques, notably steganography, in which malicious code was hidden inside an image file and extracted during the infection process. Morphisec detected and prevented multiple attacks in the first weeks of January 2024, before a related threat was publicly documented by Ukraine’s CERT-UA. The researchers also identified techniques such as code injection and “module stomping” to conceal the malware, while noting that the exact identities of the targeted Ukrainian entities could not be disclosed.

Occurrence
2024-02-26
Publication
2024-02-26T16:35:29Z
First observed
2026-09-30T16:30:48.138Z
Review status
Not assessed
Countries
FI
Updated
2026-10-02T16:30:09.889Z

E/M/R/S scores

  • EExistence0/4 · Not assessed
  • MIntent0/4 · Not assessed
  • RRussian actor link0/4 · Not assessed
  • SRussian state responsibility0/4 · Not assessed

Facts

No facts

Sources

  1. Role
    discovery_lead
    Date
    2024-02-26T16:35:29Z

    In February 2024, Morphisec reported on a cyber campaign by the threat actor UAC-0184 targeting Ukrainian entities, including organizations affiliated with Ukraine operating in Finland. The attacks involved the IDAT Loader, which delivered the Remcos Remote Access Trojan (RAT), a malware capable of remotely controlling infected computers and stealing information. The campaign used phishing emails and sophisticated defense-evasion techniques, notably steganography, in which malicious code was hidden inside an image file and extracted during the infection process. Morphisec detected and prevented multiple attacks in the first weeks of January 2024, before a related threat was publicly documented by Ukraine’s CERT-UA. The researchers also identified techniques such as code injection and “module stomping” to conceal the malware, while noting that the exact identities of the targeted Ukrainian entities could not be disclosed.