hw_641784d66fa04f85
UAC-0184-kampanj mot ukrainska enheter i Finland
I februari 2024 rapporterade Morphisec om en cyberkampanj av hotaktören UAC-0184 som riktade sig mot ukrainska enheter, inklusive organisationer med koppling till Ukraina som verkar i Finland. Attackerna involverade IDAT Loader, som levererade Remcos Remote Access Trojan (RAT), en skadlig programvara som kan fjärrstyra infekterade datorer och stjäla information. Kampanjen använde nätfiske-e-post och sofistikerade tekniker för att kringgå försvar, särskilt steganografi, där skadlig kod gömdes inuti en bildfil och extraherades under infektionsprocessen. Morphisec upptäckte och förhindrade flera attacker under de första veckorna i januari 2024, innan ett relaterat hot dokumenterades offentligt av Ukrainas CERT-UA. Forskarna identifierade också tekniker som kodinjektion och “module stomping” för att dölja skadlig programvara, och noterade att de exakta identiteterna för de riktade ukrainska enheterna inte kunde avslöjas.
E/M/R/S-poäng
- EExistens0/4 · Inte bedömd
- MAvsikt0/4 · Inte bedömd
- RKoppling till rysk aktör0/4 · Inte bedömd
- SRyska statens ansvar0/4 · Inte bedömd
Fakta
Inga fakta
Källor
-
- Roll
- discovery_lead
- Datum
- 2024-02-26T16:35:29Z
In February 2024, Morphisec reported on a cyber campaign by the threat actor UAC-0184 targeting Ukrainian entities, including organizations affiliated with Ukraine operating in Finland. The attacks involved the IDAT Loader, which delivered the Remcos Remote Access Trojan (RAT), a malware capable of remotely controlling infected computers and stealing information. The campaign used phishing emails and sophisticated defense-evasion techniques, notably steganography, in which malicious code was hidden inside an image file and extracted during the infection process. Morphisec detected and prevented multiple attacks in the first weeks of January 2024, before a related threat was publicly documented by Ukraine’s CERT-UA. The researchers also identified techniques such as code injection and “module stomping” to conceal the malware, while noting that the exact identities of the targeted Ukrainian entities could not be disclosed.