Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Cert-Ua warns of UAC-0173 attacks, deploying DCRAT to compromise Ukrainian notaries
Global Security

Cert-Ua warns of UAC-0173 attacks, deploying DCRAT to compromise Ukrainian notaries

AdminBy AdminFebruary 26, 2025No Comments2 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 26, 2025Red LakshmananNetwork Security / Intelligence Threat

On Tuesday, an emergency response group (Cert-Ua) warned an updated activity of an organized criminal group that it tracks both UAC-0173 Endkrat (AKA Darkcrystal rat).

The Ukrainian cybersecurity administration stated that it had observed the last wave of the attack since mid -January 2025.

The infection network uses phishing sheets to be sent on behalf of the Ministry of Justice of Ukraine, urging the recipients to download the executable file, which when launch leads to the deployment of malicious DCRAT software. Binary placed in R2 Cloudflare’s R2 Cloud storage service.

Cybersecurity

“So, by providing basic access to the automated notary workplace, attackers take measures to install additional tools, in particular RDPWrapper, which implements the functionality of parallel RDP sessions, which, in conjunction with utilities, allow you to set the connection RDP from the Internet directly to the computer . “Certain-Ua – Note.

The attacks are also characterized by the use of other tools and malware, such as Fiddler to intercept authentication data entered into the public registers, NMAP for scanning network and Xwomm for theft of sensitive data such as credentials and a mass boards buffer.

In addition, compromised systems are used as a pipeline to develop and send malicious sheets using the SENDMAIL console utility to further spread the attacks.

Development comes a few days after Cert-Ua attributed a subclass within Hacking Group Sandworm (AKA APT44, Seashell Blizzard and UAC -0002) with the exploitation of now requested lack of security in Microsoft Windows (Cve-2024-38213.

The attack chains were found to perform PowerShell commands responsible for displaying the bait file while starting additional useful loads in the background, including SecondBest (aka Empepast), Spark and Golang Loader called Crookbag.

Cybersecurity

Activity attributed In UAC-0212, focused suppliers from Serbia, Czech Republic and Ukraine between July 2024 and February 2025, some of them recorded more than two dozen Ukrainian enterprises specializing in the development of automated process control systems (ACST), electrical of work and freight transport.

Some of these attacks were recorded Strikeready Labs and Microsoft, the last of which tracks a group of threats nicknamed Badpilot.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025

Turning Cybersecurity Practice into Mrr Machine

June 16, 2025

Malicious Pypi Masquerade Package as chimera module for theft Aws, CI/CD and MacOS

June 16, 2025

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Meta begins showing advertisements on WhatsApp after 6 years delay with the 2018 announcement

June 17, 2025

The United States seizes $ 7.74 million with a crystallian -related IT workers of North Korea

June 16, 2025

Anubis Ransomware encrypts files and napkins, making recovery impossible even after payment

June 16, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.