SPECTR Malware Targets Ukraine Defense Forces in SickSync Campaign
ID: e4327c6d-e84d-5718-8c2b-c2a7dd4bb644
STIX ID: report--e4327c6d-e84d-5718-8c2b-c2a7dd4bb644
Feed Name: The Hacker News
CERT-UA warns of the SickSync espionage campaign attributed to UAC-0020 (Vermin), which delivers the SPECTR info-stealer via spear-phishing RAR self-extracting archives that drop a decoy PDF, a trojanized SyncThing binary carrying SPECTR, and a batch script to activate the infection. SPECTR captures screenshots, harvests files (including from USB drives), and steals credentials and messaging app data, while exfiltration is performed using the legitimate SyncThing synchronization functionality; the report also notes related activity using DarkCrystal RAT via Signal and GhostWriter Excel-based loaders.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
