Ukrainian military targeted in new Signal spear-phishing attacks
ID: 6e87ea92-b8b8-54f3-9156-6188120cebd0
STIX ID: report--6e87ea92-b8b8-54f3-9156-6188120cebd0
Feed Name: Bleeping Computer
Threat Score
CERT-UA reports a targeted campaign (tracked as UAC-0200) where attackers abuse compromised Signal accounts and the linked-devices feature to send archives containing a PDF lure and an executable (DarkTortilla cryptor/loader) that decrypts and loads the Dark Crystal RAT (DCRAT); the campaign targets Ukrainian defense industry firms and military personnel and has been active since mid-2024 with lures updated in early 2025.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
