UAC-0173 against the Notary Office of Ukraine
Essential information
- Published
- 26/02/2025 10:00
- Modified
- 26/02/2025 10:26
- Tags
- 2025-02-26 darkcrystalrat dcrat peaklight rdpwrapper state registers xworm
- Related entities
- 36 observables, 1 intrusion sets (apt), 15 techniques (mitre), 6 malware, 2 others
Description
A criminal group, UAC-0173, has resumed cyberattacks targeting notaries in Ukraine to gain unauthorized access to state registers. The attackers use phishing emails with malicious executable files to infect computers with DARKCRYSTALRAT malware. They then install additional tools like RDPWRAPPER and BORE for remote access, and employ various programs to bypass security measures and steal authentication data. The group uses compromised computers to send further malicious emails. CERT-UA, with the help of the Notary Chamber of Ukraine, has identified affected computers in six regions and prevented unauthorized actions. Authorities urge notaries to remain vigilant and report suspicious activities immediately.