UAC-0215 Phishing Campaign Targets Ukraine's Critical Sectors
ID: 5eb7429a-2eb9-590d-a6c8-ddf375c8d40f
STIX ID: report--5eb7429a-2eb9-590d-a6c8-ddf375c8d40f
Feed Name: Cyble Blog
CERT-UA attributes a phishing campaign to APT UAC-0215 that used malicious .rdp configuration files delivered via spoofed emails to target Ukrainian public authorities, major industries, and military units; when opened the .rdp files connect victims to attacker-controlled servers and expose local resources (disks, network shares, printers, COM ports, audio devices, clipboard), enabling unauthorized execution and further compromise. The campaign was first detected on 2024-10-22 with preparatory activity from August 2024, has been corroborated by multiple cybersecurity organizations, and the report recommends blocking .rdp attachments, restricting .rdp execution, firewall rules to prevent external mstsc.exe connections, and disabling RDP resource redirection.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
