Ukraine Defense Sector Under Attack Via Dark Crystal RAT
ID: 1d4199aa-d467-5f0e-a97e-1dcc2e0ec8eb
STIX ID: report--1d4199aa-d467-5f0e-a97e-1dcc2e0ec8eb
Feed Name: Dark Reading
Date Published: 2025-03-20
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Ukraine's CERT-UA warns of an active cyber-espionage campaign attributed to the group UAC-0200 using Dark Crystal RAT (DCRat). Attackers distribute archives via Signal containing a decoy PDF and a crypter called "Dark Tortilla" which decrypts and executes the RAT; victims are defense-sector organizations and members of the Defense Forces of Ukraine, and the malware enables data theft, arbitrary command execution, and remote control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
