logo

Military Tank Manual, 2017 Zero-Day Anchor Latest Ukraine Cyberattack

ID: e77df418-952b-52c1-bd04-b89d9acbce9c

STIX ID: report--e77df418-952b-52c1-bd04-b89d9acbce9c

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-04-26

Date Updated: 2026-04-21

Author: Nathan Eddy, Contributing Writer

...
...

An unknown threat actor targeted Ukrainian government entities in late 2023 by sending a malicious PowerPoint (.PPSX) via Signal that leveraged CVE-2017-8570 to execute an obfuscated script; the attack saved a loader DLL named "vpn.sessings" which loads a Cobalt Strike Beacon from attacker-controlled infrastructure (Russian VPS protected by Cloudflare with C2 registered in Warsaw). The campaign used anti-analysis and persistence techniques, masquerading as legitimate OS/app operations, and defenders are advised to scan for IoCs and ensure Office is fully patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.