UAC-0247 Hits Hospitals, Governments With Browser and WhatsApp Data Theft
ID: d7bbf8a7-e4ef-575e-aafd-d36d67ea87bf
STIX ID: report--d7bbf8a7-e4ef-575e-aafd-d36d67ea87bf
Feed Name: GBHackers
### Executive Summary The report describes a sophisticated, active campaign by UAC-0247 targeting Ukrainian municipal governments and healthcare facilities via phishing and malicious LNK/HTA loaders that execute mshta-based HTA scripts to deploy a two-stage payload: an encrypted TCP reverse shell (RAVENSHELL) followed by a C# RAT (AGINGFLY) capable of remote control, data theft (browser and WhatsApp via CHROMELEVATOR and ZAPIXDESK), and dynamic runtime command compilation; CERT-UA recommends restricting LNK/HTA/JS execution and administrative scripting utilities to mitigate the threat.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
