Lyce · Hybrid Watch

hw_641784d66fa04f85

UAC-0184-kampanj mot ukrainska enheter i Finland

I februari 2024 rapporterade Morphisec om en cyberkampanj av hotaktören UAC-0184 som riktade sig mot ukrainska enheter, inklusive organisationer med koppling till Ukraina som verkar i Finland. Attackerna involverade IDAT Loader, som levererade Remcos Remote Access Trojan (RAT), en skadlig programvara som kan fjärrstyra infekterade datorer och stjäla information. Kampanjen använde nätfiske-e-post och sofistikerade tekniker för att kringgå försvar, särskilt steganografi, där skadlig kod gömdes inuti en bildfil och extraherades under infektionsprocessen. Morphisec upptäckte och förhindrade flera attacker under de första veckorna i januari 2024, innan ett relaterat hot dokumenterades offentligt av Ukrainas CERT-UA. Forskarna identifierade också tekniker som kodinjektion och “module stomping” för att dölja skadlig programvara, och noterade att de exakta identiteterna för de riktade ukrainska enheterna inte kunde avslöjas.

Händelse
2024-02-26
Publicering
2024-02-26T16:35:29Z
Först observerad
2026-09-30T16:30:48.138Z
Granskningsstatus
Inte bedömd
Länder
FI
Uppdaterad
2026-10-02T16:30:09.889Z

E/M/R/S-poäng

  • EExistens0/4 · Inte bedömd
  • MAvsikt0/4 · Inte bedömd
  • RKoppling till rysk aktör0/4 · Inte bedömd
  • SRyska statens ansvar0/4 · Inte bedömd

Fakta

Inga fakta

Källor

  1. Roll
    discovery_lead
    Datum
    2024-02-26T16:35:29Z

    In February 2024, Morphisec reported on a cyber campaign by the threat actor UAC-0184 targeting Ukrainian entities, including organizations affiliated with Ukraine operating in Finland. The attacks involved the IDAT Loader, which delivered the Remcos Remote Access Trojan (RAT), a malware capable of remotely controlling infected computers and stealing information. The campaign used phishing emails and sophisticated defense-evasion techniques, notably steganography, in which malicious code was hidden inside an image file and extracted during the infection process. Morphisec detected and prevented multiple attacks in the first weeks of January 2024, before a related threat was publicly documented by Ukraine’s CERT-UA. The researchers also identified techniques such as code injection and “module stomping” to conceal the malware, while noting that the exact identities of the targeted Ukrainian entities could not be disclosed.