September 22, 2023

CERT-UA from Ukraine said that Russia-linked threat actors have breached multiple government websites earlier this week, resulting in content modification. The government experts attribute the attack to the UAC-0056 group (DEV-0586, unc2589, Nodaria, or Lorec53).

The SSSCIP’s National Cybersecurity Coordination Center along with the Cyber ​​Police are working together to lock out the threats and investigate the security breaches.

The state-sponsored hackers used a web shell created no later than December 23, 2021, to deploy multiple backdoors. The nation-state actor employed the SSH backdoor CredPump (PAM module) to achieve remote SSH access and logging of logins and passwords when connecting via SSH.

The attackers also used the HoaxPen and HoaxApe backdoors, experts discovered that the malicious codes were in the form of a module for the Apache web server and were installed in February 2022.

The alert states that attackers employed GOST (Go Simple Tunnel) and the Ngrok program in the early stages of the attack.

The UAC-0056 APT group has been active since at least March 2021, it focuses on Ukraine, despite it has been involved in attacks on targets in Kyrgyzstan and Georgia.It has been observed deploying a new information stealer dubbed Graphiron in attacks against Ukraine.

Indicators of Compromise

  • 0dfb7f25df748957a15448214bac3128
  • 2cc1100de4a9fdee79a9eaa633eeba2e
  • 167fe17438fdf87d2931c1128e07fac7
  • d8ea9402b705c60e288da43d92000286
  • 62063ffe877788f9863d9166b3915934
  • 5967e1c4c213c8a512702917c41d9ece
  • ea9e36ce72b0faddb784eb9e41c5f3af
  • f102730f7ba20c30c9e077f8e1cc0c8b
  • 00a1e595acb40b42bb7df3135d083d77
  • 38073229b776c472978061d794bed23c
  • a84a4443395eb9c20e59ac6491aedfe4
  • 6c4d220fc8368e6e6ccee21b45220dd2

Leave a Reply

%d bloggers like this: