Ukraine Targeted in Cyberattack Exploiting 7-Year-Old Microsoft Office Flaw
ID: 0ae64eeb-4c96-5b51-805f-856ae6014314
STIX ID: report--0ae64eeb-4c96-5b51-805f-856ae6014314
Feed Name: The Hacker News
Threat Score
Researchers found a late-2023 targeted operation against Ukrainian personnel using a PowerPoint (PPSX) exploiting CVE-2017-8570 to load remote scripts that deploy a payload impersonating Cisco AnyConnect and inject a cracked Cobalt Strike Beacon, communicating with C2 domains; separately, CERT-UA attributes disruptive campaigns against ~20 Ukrainian critical infrastructure suppliers to Sandworm (GRU-linked), employing malware families like Kapeka/BIASBOAT, GOSSIPFLOW and LOADGRIP.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
