216.73.216.197

UAC-0173 against the Notary Office of Ukraine

· Published 26/02/2025 10:00 · Modified 26/02/2025 10:26

Export JSON

Essential information

Published
26/02/2025 10:00
Modified
26/02/2025 10:26
Tags
2025-02-26 darkcrystalrat dcrat peaklight rdpwrapper state registers xworm
Related entities
36 observables, 1 intrusion sets (apt), 15 techniques (mitre), 6 malware, 2 others

Description

A criminal group, UAC-0173, has resumed cyberattacks targeting notaries in Ukraine to gain unauthorized access to . The attackers use phishing emails with malicious executable files to infect computers with malware. They then install additional tools like and BORE for remote access, and employ various programs to bypass security measures and steal authentication data. The group uses compromised computers to send further malicious emails. CERT-UA, with the help of the Notary Chamber of Ukraine, has identified affected computers in six regions and prevented unauthorized actions. Authorities urge notaries to remain vigilant and report suspicious activities immediately.

External references