logo

UAC-0057 Targets Ukraine and Poland with Weaponized Archives and Evolving Implants

ID: 7f133f1b-9f1f-5256-99f7-9b56a1b6d1f0

STIX ID: report--7f133f1b-9f1f-5256-99f7-9b56a1b6d1f0

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2025-08-22

Date Updated: 2026-04-22

Author: Ddos

...
...

HarfangLab reports two linked cyber-espionage campaigns attributed to UAC-0057 (UNC1151/FrostyNeighbor/Ghostwriter) active since April 2025 that targeted Ukraine and Poland with weaponized XLS files containing VBA macros which deploy obfuscated C#/C++ DLL implants via CAB/LNK-based execution chains; implants collected system telemetry and exfiltrated to attacker-controlled C2s (including Cloudflare-backed domains and abused Slack webhooks), with later variants using Cobalt Strike for persistence and lateral movement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.