Site icon TheCyberThrone

UAC-0099 targets Ukraine with CVE-2023-38831

Advertisements

A threat actor goes by the name UAC-0099 targeting Ukraine by exploiting a high severity vulnerability in WinRAR to deliver the LONEPAGE malware.

UAC-0099 targeting Ukraine since 2022, it was spotted targeting Ukrainian employees working for companies outside of Ukraine. In May 2023, CERT-UA warned of cyber espionage attacks carried out by UAC-0099 against state organizations and media representatives of Ukraine.

The group used different infection vectors, the researchers detailed phishing attacks using HTA, RAR, and LNK file attachments. The last-stage malware is the Visual Basic Script (VBS) malware LONEPAGE.

Advertisements

The attack chains leveraged phishing messages containing HTA, RAR, and LNK file attachments that led to the deployment of the Visual Basic Script (VBS) malware LONEPAGE. The malicious code can retrieve additional payloads, including keyloggers and info-stealers.

Deep Instinct reported that the group UAC-0099 exploited the WinRAR flaw CVE-2023-38831, a POC for the issue is available on GitHub. The WinRAR version 6.23 which was released on August 2, 2023, addressed the vulnerability.

Advertisements

Despite the different initial infection vectors, the core infection is the same — they rely on PowerShell and the creation of a scheduled task that executes a VBS file.The researchers pointed out that this attack technique can also deceive security-savvy victims. The POC for the vulnerability in GitHub. A patched WinRAR (version 6.23) was released on August 2, 2023.

Exit mobile version