logo

Hackers-for-hire target Ukrainian notaries to manipulate state registries

ID: cff7bf2d-90cc-5654-bbe5-fd9f1c0bcd6c

STIX ID: report--cff7bf2d-90cc-5654-bbe5-fd9f1c0bcd6c

Feed Name: The Record from Recorded Future News

Threat Score
78/100

Date Published: 2025-02-26

Date Updated: 2026-05-01

...
...

CERT‑UA warns that the UAC‑0173 group has run phishing campaigns since January against Ukrainian notaries, delivering DarkCrystal backdoor (and previously AsyncRAT) to achieve remote access, credential theft, and attempted manipulation of state registries; a separate group, UAC‑0212 (linked to Sandworm), targeted suppliers of industrial control components using EmpirePast, Spark and CrookBag. Authorities identified affected hosts across multiple regions, blocked unauthorized registry changes in several cases, and attribute motives ranging from financially motivated contracting to potential targeting of critical industrial infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.