FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine
ID: 5dd76de0-ad54-5631-bec3-806f84e3e7b2
STIX ID: report--5dd76de0-ad54-5631-bec3-806f84e3e7b2
Feed Name: The Hacker News
Cloudflare disrupted a month-long, Ukraine-targeted phishing campaign attributed to the Russia-aligned cluster "FlyingYeti" (tracked by CERT-UA as UAC-0149) that used debt-themed lures to trick victims into downloading a RAR archive which weaponized CVE-2023-38831 to install the PowerShell backdoor COOKBOX. The campaign leveraged Cloudflare Workers, GitHub pages impersonating local services, and DDNS C2 infrastructure (postdock.serveftp.com) to stage payloads and receive PowerShell cmdlets, representing an active, targeted APT-style operation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
