CERT-UA warns of cyber espionage against the Ukrainian defense industry using Dark Crystal RAT
ID: 615b8aab-90d2-5de3-8ac0-72dd4083d83d
STIX ID: report--615b8aab-90d2-5de3-8ac0-72dd4083d83d
Feed Name: Security Affairs
Threat Score
CERT-UA warns of an active cyber-espionage campaign (tracked as UAC-0200) targeting Ukraine's defense industry and Defense Forces using Dark Crystal RAT (DCRat). Threat actors distribute password-protected archives via Signal containing a decoy (fake PDF) and a DarkTortilla loader that executes a macro/PowerShell chain to download and launch a .NET bootloader and DCRat; recent lures focus on UAVs and electronic warfare, and CERT-UA has published associated IoCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
