logo

SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign

ID: e4327c6d-e84d-5718-8c2b-c2a7dd4bb644

STIX ID: report--e4327c6d-e84d-5718-8c2b-c2a7dd4bb644

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2024-06-07

Date Updated: 2026-05-06

Author: [email protected] (The Hacker News)

...
...

CERT-UA warns of the SickSync espionage campaign attributed to UAC-0020 (Vermin), which delivers the SPECTR info-stealer via spear-phishing RAR self-extracting archives that drop a decoy PDF, a trojanized SyncThing binary carrying SPECTR, and a batch script to activate the infection. SPECTR captures screenshots, harvests files (including from USB drives), and steals credentials and messaging app data, while exfiltration is performed using the legitimate SyncThing synchronization functionality; the report also notes related activity using DarkCrystal RAT via Signal and GhostWriter Excel-based loaders.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.