Military Tank Manual, 2017 Zero-Day Anchor Latest Ukraine Cyberattack
ID: e77df418-952b-52c1-bd04-b89d9acbce9c
STIX ID: report--e77df418-952b-52c1-bd04-b89d9acbce9c
Feed Name: Dark Reading
An unknown threat actor targeted Ukrainian government entities in late 2023 by sending a malicious PowerPoint (.PPSX) via Signal that leveraged CVE-2017-8570 to execute an obfuscated script; the attack saved a loader DLL named "vpn.sessings" which loads a Cobalt Strike Beacon from attacker-controlled infrastructure (Russian VPS protected by Cloudflare with C2 registered in Warsaw). The campaign used anti-analysis and persistence techniques, masquerading as legitimate OS/app operations, and defenders are advised to scan for IoCs and ensure Office is fully patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
