logo

CERT-UA warns of cyber espionage against the Ukrainian defense industry using Dark Crystal RAT

ID: 615b8aab-90d2-5de3-8ac0-72dd4083d83d

STIX ID: report--615b8aab-90d2-5de3-8ac0-72dd4083d83d

Feed Name: Security Affairs

Threat Score
78/100

Date Published: 2025-03-20

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CERT-UA warns of an active cyber-espionage campaign (tracked as UAC-0200) targeting Ukraine's defense industry and Defense Forces using Dark Crystal RAT (DCRat). Threat actors distribute password-protected archives via Signal containing a decoy (fake PDF) and a DarkTortilla loader that executes a macro/PowerShell chain to download and launch a .NET bootloader and DCRat; recent lures focus on UAVs and electronic warfare, and CERT-UA has published associated IoCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.