logo

UAC-0184 Hackers Abuse bitsadmin and HTA Files In Malware Campaign

ID: a2c5725a-fa82-595a-898f-e954ec5329e4

STIX ID: report--a2c5725a-fa82-595a-898f-e954ec5329e4

Feed Name: Cyber Press

Threat Score
88/100

Date Published: 2026-05-19

Date Updated: 2026-05-19

Author: Varshini

...
...

UAC-0184 (Russian-aligned) ran a sophisticated, multi-stage campaign against Ukrainian military targets using Viber-delivered lures and malicious ZIP/LNK/HTA files that abuse bitsadmin and PowerShell; the attack leverages DLL sideloading, steganographic payload hiding (fake PNG/IDAT parsing + XOR + LZNT1), and sideloading into signed utilities to gain network-capable persistence. Indicators provided include a primary ZIP SHA-256 (81d93004a02a455af01b0f709e34d5134108ec350f9391dc0f91a00a54998590) and a staging IP (169.40.135.35).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.