Russia-linked APT UAC-0184 uses Viber to spy on Ukrainian military in 2025
ID: eafcf78e-d8ec-5c81-8b0a-9c067db98b71
STIX ID: report--eafcf78e-d8ec-5c81-8b0a-9c067db98b71
Feed Name: Security Affairs
Russia-linked APT UAC-0184 conducted a targeted 2025 phishing campaign against Ukraine’s Verkhovna Rada and military using Viber messages with malicious ZIP attachments (e.g., A2393.zip) that contained deceptive LNK shortcuts and PowerShell scripts; the multi-stage chain sideloaded malicious DLLs, used HijackLoader to deploy the Remcos RAT via legitimate processes (CFlux.exe, Chime.exe), and employed evasion techniques (non-standard control flow, module stomping, encrypted payloads embedded in PNGs) to perform espionage and data theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
