Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » UAC-0099 uses WinRAR vulnerability to exploit LONEPAGE malware to attack Ukrainian companies
    Cyber Security

    UAC-0099 uses WinRAR vulnerability to exploit LONEPAGE malware to attack Ukrainian companies

    techempireBy techempireNo Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportDecember 22, 2023Editorial DepartmentMalware/cyber attacks

    WinRAR vulnerability

    Threat actors are called UAC-0099 Related to ongoing attacks targeting Ukraine, some of which exploit high-severity flaws in WinRAR software to spread malware called LONEPAGE.

    “Threat actors are targeting Ukrainian employees working at companies outside Ukraine,” cybersecurity firm Deep Instinct said in an analysis on Thursday.

    UAC-0099 was first documented by the Computer Emergency Response Team of Ukraine (CERT-UA) in June 2023, detailing its espionage-motivated attacks on state organizations and media entities.

    Upcoming webinars

    From user to administrator: Learn how hackers gain total control

    Learn the secret tactics hackers use to become administrators and how to detect and stop it before it’s too late. Register now for our webinar.

    Join now

    The attack chain leveraged phishing messages containing HTA, RAR, and LNK file attachments, leading to the deployment of LONEPAGE, a Visual Basic Script (VBS) malware capable of contacting a command and control (C2) server to retrieve other Payloads such as keyloggers, stealers, and screenshot malware.

    “Between 2022 and 2023, the above-mentioned organization received unauthorized remote access to dozens of computers in Ukraine,” CERT-UA said at the time.

    New analysis from Deep Instinct shows that the use of HTA accessories is just one of three different infection chains, with the other two utilizing self-extracting (SFX) archives and booby-trapped ZIP archives. ZIP archives exploit the WinRAR vulnerability (CVE-2023-38831, CVSS score: 7.8) to distribute LONEPAGE.

    WinRAR vulnerability

    In the former, the SFX file contains a LNK shortcut that disguises itself as a court subpoena DOCX file while using an icon of Microsoft WordPad to trick the victim into opening it, which results in the execution of malicious PowerShell code, thereby releasing the LONEPAGE malware.

    Another attack sequence used a specially crafted ZIP archive that was vulnerable to CVE-2023-38831. Deep Instinct discovered UAC-0099 on August 5, 2023, three days after WinRAR maintainers released a patch for the bug. of two such artifacts.

    Internet security

    “The strategy used by ‘UAC-0099’ is simple but effective,” the company said. “Although the initial infection vector is different, the core infections are the same – they rely on PowerShell and the creation of scheduled tasks that execute VBS files.”

    This development comes as CERT-UA warns of a new wave of phishing messages purporting to be indebted to Kyivstar and designed to deliver a remote access Trojan called Remcos RAT. The agency attributed the activity to UAC-0050.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.