UAC-0173 Resumes Targeted Cyberattacks On Ukrainian Notary Offices
ID: cbd2bcad-d7a9-58c9-bfc5-9541b9a3803d
STIX ID: report--cbd2bcad-d7a9-58c9-bfc5-9541b9a3803d
Feed Name: Cyble Blog
Threat Score
CERT-UA warns that the financially motivated criminal group UAC-0173 resumed targeted phishing attacks against Ukrainian notary offices in early 2025, distributing malicious executables (including DARKCRYSTALRAT) to achieve remote access, install RDP backdoors and persistence, steal credentials (XWORM, FIDDLER), and attempt unauthorized modifications of state registers; the report includes file hashes, malicious domains/IPs, persistence paths, and mitigation guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
