UAC-0063
· Published 21/12/2025 09:53 · Modified 29/05/2026 12:19
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 09:53
- Modified
- 29/05/2026 12:19
- Updated at
- 29/05/2026 12:19
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 25 attack patterns (mitre), 5 malware, 1 sectors, 12 countries, 25 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
24 MITREs 4 Malwares 1 APTPublished 29/01/2025 13:06 · Modified 29/01/2025 14:02
-
11 MITREs 2 Malwares 12 Observables 1 APTPublished 13/01/2025 16:41 · Modified 14/01/2025 08:46
Attack patterns (MITRE) (25 / 30)
-
T1027.002 usesSoftware Packing
-
T1056.001 usesKeylogging
-
T1005 usesData from Local System
-
T1120 usesPeripheral Device Discovery
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1053.005 usesScheduled Task
-
T1566 usesPhishing
-
T1573.002 usesAsymmetric Cryptography
-
T1543.003 usesWindows Service
-
T1204.002 usesMalicious File
-
T1071.001 usesWeb Protocols
-
T1571 usesNon-Standard Port
-
T1132 usesData Encoding
-
T1074 usesData Staged
-
T1082 usesSystem Information Discovery
-
T1036 usesMasquerading
-
T1573.001 usesSymmetric Cryptography
-
T1204 usesUser Execution
-
T1105 usesIngress Tool Transfer
-
T1555 usesCredentials from Password Stores
-
T1053 usesScheduled Task/Job
-
T1027 usesObfuscated Files or Information
-
T1083 usesFile and Directory Discovery
-
T1518 usesSoftware Discovery
-
T1112 usesModify Registry
Malware (5)
-
DownExPyer usesFamilyPublished 29/01/2025 13:06 · Modified 29/01/2025 13:06
-
HATVIBE usesFamilyPublished 22/05/2025 21:54 · Modified 22/05/2025 21:54
-
CHERRYSPY usesFamilyPublished 22/05/2025 21:54 · Modified 22/05/2025 21:54
-
PyPlunderPlug usesFamilyPublished 22/05/2025 21:54 · Modified 22/05/2025 21:54
-
LOGPIE usesFamilyPublished 22/05/2025 21:54 · Modified 22/05/2025 21:54
Sectors (1)
- Government targets
Countries (12)
- Kyrgyzstan targets
- Georgia targets
- Belgium targets
- Uzbekistan targets
- Germany targets
- Kazakhstan targets
- Turkmenistan targets
- Afghanistan targets
- Netherlands targets
- Tajikistan targets
- Mongolia targets
- Romania targets
Indicators (25 / 39)
-
background-services.netindicates -
efc99e6f3cdd10313c52a8ad099424e3f39ab85b75375b8db82717d61c7f0118indicates -
3b87dc25a11b6268019d5eae49a6b93271dfdc262f2607cfefa35d196f724997indicates -
internalsecurity.usindicates -
automation-embedding.comindicates -
apt_UAC0063_HATVIBE_loader_obfuscated_VBAindicates -
06e4084e2d043f216c0bc7931781ce3e1cea4eca1b6092c0e34b01a89e2a6deaindicates -
0fa7e3ffb8a9ca246cc1f1e3f6118ced7a7b785de510d777b316dfcefdddb0beindicates -
332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725indicates -
d21f2469cacf40de30e62b372e9dd576bdbd95acindicates -
e3a0be8852d77771dc3f44f3e9a051e7fe56547b569aad5a178ae44ef31713b9indicates -
retaildemo.infoindicates -
lookup.inkindicates -
certstorecheck.htindicates -
https://cloud-mail.ink/download.phpindicates -
937b30aef519c49dd523736c2af94489bab6d9f9indicates -
bbb678f7214580d290db3b6aeb1fab09df3d680aindicates -
rss-feed-monitoring.comindicates -
fd78051817b5e2375c92d14588f9a4ba1adc92cc1564e55e6150ae350ed6c889indicates -
tieringservice.comindicates -
apt_UAC0063_HATVIBE_loader_deobfuscated_VBAindicates -
etaildemo.infoindicates -
c61e9326421d05d62cafd6c04041ab1a8f57c0a21d424b9ca04b6a1fc275af19indicates -
2fa44b62209f7181ad91a06af294f13daa096b29indicates -
underwearshopfor.comindicates