Tag: CHERRYSPY Malware

Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia
News

Russian Hackers Deploy HATVIBE and CHERRYSPY Malware Across Europe and Asia

Russian-affiliated threat actors have been implicated in a cyber espionage campaign targeting Central Asian, East Asian, and European organizations. The activity cluster, which has been given the moniker TAG-110 by Recorded Future's Insikt Group, coincides with a threat group that the Computer Emergency Response Team of Ukraine (CERT-UA) tracks as UAC-0063, which overlaps with APT28. Since at least 2021, the hacker team has been in operation. According to a report released by the cybersecurity firm on Thursday, TAG-110 mostly targets government agencies, human rights organizations, and educational institutions using the proprietary malware tools HATVIBE and CHERRYSPY. HATVIBE serves as a loader for CHERRYSPY, a Python backdoor for espionage and data exfiltration read more about Russ...
Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware
News

Ukrainian Institutions Targeted Using HATVIBE and CHERRYSPY Malware

The HATVIBE and CHERRYSPY malware is being used in a spear-phishing effort against a scientific research center in Ukraine, according to a warning from the Computer Emergency Response Team of Ukraine (CERT-UA). The organization linked the attack to a threat actor it monitors under the handle UAC-0063, which was previously seen utilizing keyloggers and backdoors to target other government agencies in an effort to obtain sensitive data. The assault is typified by the use of an employee's hijacked email account to send phishing messages with a Microsoft Word (DOCX) attachment that contains macros to "dozens" of recipients. When the document is opened and macros are enabled, an encoded HTML Application (HTA) called HATVIBE is launched. This HTA establishes persistence on the host thr...