logo

UAC-0173 Resumes Targeted Cyberattacks On Ukrainian Notary Offices

ID: cbd2bcad-d7a9-58c9-bfc5-9541b9a3803d

STIX ID: report--cbd2bcad-d7a9-58c9-bfc5-9541b9a3803d

Feed Name: Cyble Blog

Threat Score
78/100

Date Published: 2025-10-21

Date Updated: 2026-07-16

...
...

CERT-UA warns that the financially motivated criminal group UAC-0173 resumed targeted phishing attacks against Ukrainian notary offices in early 2025, distributing malicious executables (including DARKCRYSTALRAT) to achieve remote access, install RDP backdoors and persistence, steal credentials (XWORM, FIDDLER), and attempt unauthorized modifications of state registers; the report includes file hashes, malicious domains/IPs, persistence paths, and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.