logo

Ukrainian Systems Hit by Cobalt Strike Via a Malicious Excel File

ID: bb3d74b4-4760-5325-8a44-342e053bb18f

STIX ID: report--bb3d74b4-4760-5325-8a44-342e053bb18f

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-04

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Fortinet researchers observed a Ukraine-targeted campaign using a Ukrainian-themed Excel file with an embedded VBA macro that, if enabled, drops a ConfuserEX-obfuscated DLL downloader. The downloader performs AV/sandbox checks, geo-fences payload delivery to devices in Ukraine, and fetches a second-stage payload that culminates in deploying the Cobalt Strike post-exploitation toolkit; the report highlights evasion and persistence measures and situates the activity within a pattern of prior Ukraine-focused attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.