Information-stealing malware is being used in a fresh wave of cyberattacks against Ukrainian institutions, according to the Computer Emergency Response Team of Ukraine (CERT-UA).
According to the CIA, the operation targets local self-government organizations, law enforcement organizations, and military formations, especially those situated close to Ukraine’s eastern border.
The attacks entail sending out phishing emails that contain a Microsoft Excel spreadsheet (XLSM) with macro functionality. When the spreadsheet is opened, two pieces of malware are deployed: a PowerShell script from the GitHub repository PSSW100AVB (“Powershell Scripts With 100% AV Bypass”) that opens a reverse shell, and an as-yet-unknown stealer known as GIFTEDCROOK.
According to CERT-UA, file names and email subject lines make reference to delicate and pertinent topics like demining, administrative penalties, the production of UAVs, and compensation for property damage read more about UAC-0226 Deploys GIFTEDCROOK Stealer via Malicious Excel Files Targeting Ukraine.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
