UAC-0184 Hackers Abuse bitsadmin and HTA Files In Malware Campaign
ID: a2c5725a-fa82-595a-898f-e954ec5329e4
STIX ID: report--a2c5725a-fa82-595a-898f-e954ec5329e4
Feed Name: Cyber Press
UAC-0184 (Russian-aligned) ran a sophisticated, multi-stage campaign against Ukrainian military targets using Viber-delivered lures and malicious ZIP/LNK/HTA files that abuse bitsadmin and PowerShell; the attack leverages DLL sideloading, steganographic payload hiding (fake PNG/IDAT parsing + XOR + LZNT1), and sideloading into signed utilities to gain network-capable persistence. Indicators provided include a primary ZIP SHA-256 (81d93004a02a455af01b0f709e34d5134108ec350f9391dc0f91a00a54998590) and a staging IP (169.40.135.35).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
