logo

Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw

ID: 0ae64eeb-4c96-5b51-805f-856ae6014314

STIX ID: report--0ae64eeb-4c96-5b51-805f-856ae6014314

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-04-27

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Researchers found a late-2023 targeted operation against Ukrainian personnel using a PowerPoint (PPSX) exploiting CVE-2017-8570 to load remote scripts that deploy a payload impersonating Cisco AnyConnect and inject a cracked Cobalt Strike Beacon, communicating with C2 domains; separately, CERT-UA attributes disruptive campaigns against ~20 Ukrainian critical infrastructure suppliers to Sandworm (GRU-linked), employing malware families like Kapeka/BIASBOAT, GOSSIPFLOW and LOADGRIP.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.