Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Chinese hackers unfold the back of Marsssnake in a perennial attack on the Saudi Organization

May 20, 2025

Based on GO based on malicious programs deployed Xmrig Miner on hosts Linux through Redis configuration abuse

May 20, 2025

Malicious Pypi Packages Operating Instagram and Tiktok API to verify users’ accounts

May 20, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cert-Ua warns of UAC-0173 attacks, deploying DCRAT to compromise Ukrainian notaries
Global Security

Cert-Ua warns of UAC-0173 attacks, deploying DCRAT to compromise Ukrainian notaries

AdminBy AdminFebruary 26, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 26, 2025Red LakshmananNetwork Security / Intelligence Threat

On Tuesday, an emergency response group (Cert-Ua) warned an updated activity of an organized criminal group that it tracks both UAC-0173 Endkrat (AKA Darkcrystal rat).

The Ukrainian cybersecurity administration stated that it had observed the last wave of the attack since mid -January 2025.

The infection network uses phishing sheets to be sent on behalf of the Ministry of Justice of Ukraine, urging the recipients to download the executable file, which when launch leads to the deployment of malicious DCRAT software. Binary placed in R2 Cloudflare’s R2 Cloud storage service.

Cybersecurity

“So, by providing basic access to the automated notary workplace, attackers take measures to install additional tools, in particular RDPWrapper, which implements the functionality of parallel RDP sessions, which, in conjunction with utilities, allow you to set the connection RDP from the Internet directly to the computer . “Certain-Ua – Note.

The attacks are also characterized by the use of other tools and malware, such as Fiddler to intercept authentication data entered into the public registers, NMAP for scanning network and Xwomm for theft of sensitive data such as credentials and a mass boards buffer.

In addition, compromised systems are used as a pipeline to develop and send malicious sheets using the SENDMAIL console utility to further spread the attacks.

Development comes a few days after Cert-Ua attributed a subclass within Hacking Group Sandworm (AKA APT44, Seashell Blizzard and UAC -0002) with the exploitation of now requested lack of security in Microsoft Windows (Cve-2024-38213.

The attack chains were found to perform PowerShell commands responsible for displaying the bait file while starting additional useful loads in the background, including SecondBest (aka Empepast), Spark and Golang Loader called Crookbag.

Cybersecurity

Activity attributed In UAC-0212, focused suppliers from Serbia, Czech Republic and Ukraine between July 2024 and February 2025, some of them recorded more than two dozen Ukrainian enterprises specializing in the development of automated process control systems (ACST), electrical of work and freight transport.

Some of these attacks were recorded Strikeready Labs and Microsoft, the last of which tracks a group of threats nicknamed Badpilot.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Chinese hackers unfold the back of Marsssnake in a perennial attack on the Saudi Organization

May 20, 2025

Based on GO based on malicious programs deployed Xmrig Miner on hosts Linux through Redis configuration abuse

May 20, 2025

Malicious Pypi Packages Operating Instagram and Tiktok API to verify users’ accounts

May 20, 2025

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Chinese hackers unfold the back of Marsssnake in a perennial attack on the Saudi Organization

May 20, 2025

Based on GO based on malicious programs deployed Xmrig Miner on hosts Linux through Redis configuration abuse

May 20, 2025

Malicious Pypi Packages Operating Instagram and Tiktok API to verify users’ accounts

May 20, 2025

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Chinese hackers unfold the back of Marsssnake in a perennial attack on the Saudi Organization

May 20, 2025

Based on GO based on malicious programs deployed Xmrig Miner on hosts Linux through Redis configuration abuse

May 20, 2025

Malicious Pypi Packages Operating Instagram and Tiktok API to verify users’ accounts

May 20, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.