The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning about potential cyberattacks against Ukrainian governmental institutions using the approved remote access program Remcos.
The agency has identified the threat actor behind the widespread phishing campaign as UAC-0050 and based on the toolset used, they believe the action was probably spied-related.
The fake emails that begin the infection chain contain a fake RAR archive and purport to be from the Ukrainian telecom business Ukrtelecom.
The file contains two files: a text file providing the password to open the password-protected RAR archive and read the complete article CERT-UA Alerts Ukrainian State Authorities of Remcos Software-Fueled Cyber Attacks.
Keep up with the most recent cybersecurity news and trends by following ReconBee.com for these kinds of cybersecurity awareness and education blogs.
