UAC-0057 Targets Ukraine and Poland with Weaponized Archives and Evolving Implants
ID: 7f133f1b-9f1f-5256-99f7-9b56a1b6d1f0
STIX ID: report--7f133f1b-9f1f-5256-99f7-9b56a1b6d1f0
Feed Name: securityonline.info
HarfangLab reports two linked cyber-espionage campaigns attributed to UAC-0057 (UNC1151/FrostyNeighbor/Ghostwriter) active since April 2025 that targeted Ukraine and Poland with weaponized XLS files containing VBA macros which deploy obfuscated C#/C++ DLL implants via CAB/LNK-based execution chains; implants collected system telemetry and exfiltrated to attacker-controlled C2s (including Cloudflare-backed domains and abused Slack webhooks), with later variants using Cobalt Strike for persistence and lateral movement.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
