UAC-0050 Group Using Remcos RAT to Attack Government Agencies
ID: dc628f51-1057-5884-bf7c-83fd426d83d2
STIX ID: report--dc628f51-1057-5884-bf7c-83fd426d83d2
Feed Name: GBHackers
Uptycs researchers uncovered a focused campaign by UAC-0050 deploying Remcos RAT (v4.9.2 Pro) against Ukrainian government targets via a crafted LNK that triggers an HTA -> obfuscated VBScript -> PowerShell chain to fetch word_update.exe; the malware uses pipe-based IPC and in-memory execution to load Remcos into explorer.exe, achieves persistence via startup LNKs and copies, and exfiltrates browser cookies and credentials. The report includes file and behavior artifacts (e.g., 6.hta, word_update.exe, fmTask_dbg.exe, %appdata% drop locations) and recommends email filtering, behavioral monitoring, and system hardening to detect and block such RAT activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
