logo

FlyingYeti Exploits WinRAR Vulnerability to Deliver COOKBOX Malware in Ukraine

ID: 5dd76de0-ad54-5631-bec3-806f84e3e7b2

STIX ID: report--5dd76de0-ad54-5631-bec3-806f84e3e7b2

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-05-30

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Cloudflare disrupted a month-long, Ukraine-targeted phishing campaign attributed to the Russia-aligned cluster "FlyingYeti" (tracked by CERT-UA as UAC-0149) that used debt-themed lures to trick victims into downloading a RAR archive which weaponized CVE-2023-38831 to install the PowerShell backdoor COOKBOX. The campaign leveraged Cloudflare Workers, GitHub pages impersonating local services, and DDNS C2 infrastructure (postdock.serveftp.com) to stage payloads and receive PowerShell cmdlets, representing an active, targeted APT-style operation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.