privacysavvy

privacysavvy

Friday, December 1, 2023

[New post] UAC-0050 Attack Detection: Hackers Launch Another Targeted Campaign Spreading Remcos RAT

Site logo image Malware Devil posted: "Hard on the heels of the phishing attack impersonating the Security Service of Ukraine and using Remcos RAT, the hacking collective identified as UAC-0050 launched another adversary campaign against Ukraine leveraging the phishing attack vector. In these " Malware Devil

UAC-0050 Attack Detection: Hackers Launch Another Targeted Campaign Spreading Remcos RAT

Malware Devil

Dec 1

Hard on the heels of the phishing attack impersonating the Security Service of Ukraine and using Remcos RAT, the hacking collective identified as UAC-0050 launched another adversary campaign against Ukraine leveraging the phishing attack vector. In these attacks targeting 15,000+ users hackers massively send emails with a subject and attachment lures related to a summons to court topic aimed to spread Remcos RAT on the impacted systems. 

Phishing Attack Analysis Attributed to UAC-0050 and Spreading Remcos RAT

The latest CERT-UA#8150 alert covers another malicious activity by the UAC-0050 threat actors distributing Remcos RAT malware. Adversaries abuse the summons to court topic striving to lure targeted users into opening the malicious email content and an RAR attachment. The latter contains a password-encrypted file with a DOC file and a malicious macro. Once activated, the code macro runs an executable file on the compromised machine via explorer.exe and the SMB protocol. This EXE file is obfuscated using the SmartAssembly .NET-based software designed for decrypting and launching Remcos RAT.

Notably, the latest campaign by UAC-0050 targets at least 15,000 users using legitimate compromised email accounts of one of the Ukrainian judicial authorities. Considering the scope of potential victims, CERT-UA stresses the importance of taking urgent measures to remediate the threat.

Detect the UAC-0050 Campaign Covered in the CERT-UA#8150 Alert

With the increasing number of UAC-0050 attacks against Ukraine, defenders are searching for ways to reinforce their threat detection capabilities and safeguard the infrastructure against adversary intrusions. SOC Prime Platform offers a curated list of detection algorithms to thwart attacks by the UAC-0050 group described in the latest CERT-UA alert. Use the link below to drill down to the list of relevant Sigma rules filtered by the custom tag "CERT-UA#8150" matching the security notice ID:

Detection content for UAC-0050 attacks covered in the CERT-UA#8150 alert 

All Sigma rules are aligned with the MITRE ATT&CK® framework, enriched with tailored intelligence, and can leveraged across dozens of SIEM, EDR, XDR, and Data Lake solutions.

Looking for more detection content to withstand existing phishing attacks linked to the UAC-0050 hacking collective? Click Explore Detections to reach the entire collection of SOC content from Threat Detection Marketplace for UAC-0050 attack detection and always stay ahead of adversaries. 

Comment

Manage your email settings or unsubscribe.

Trouble clicking? Copy and paste this URL into your browser:
https://devi.ly/uac-0050-attack-detection-hackers-launch-another-targeted-campaign-spreading-remcos-rat/

WordPress.com and Jetpack Logos

Get the Jetpack app to use Reader anywhere, anytime

Follow your favorite sites, save posts to read later, and get real-time notifications for likes and comments.

Download Jetpack on Google Play Download Jetpack from the App Store
WordPress.com on Twitter WordPress.com on Facebook WordPress.com on Instagram WordPress.com on YouTube
WordPress.com Logo and Wordmark title=

Automattic, Inc. - 60 29th St. #343, San Francisco, CA 94110  

at December 01, 2023
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest

No comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments (Atom)

End of week Artemis update - Jun 26th 2026

A round-up of our ILS focused news from this week ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ...

  • Dork List
    ...
  • End of week Artemis update - July 18th 2025
    A round-up of our ILS focused news from this week ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌...
  • Artemis London 2025: Under two months to go
    Register now to attend at the lowest price ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌ ‌...

Search This Blog

  • Home

About Me

privacysavvy
View my complete profile

Report Abuse

Blog Archive

  • June 2026 (66)
  • May 2026 (73)
  • April 2026 (94)
  • March 2026 (92)
  • February 2026 (76)
  • January 2026 (77)
  • December 2025 (79)
  • November 2025 (73)
  • October 2025 (88)
  • September 2025 (79)
  • August 2025 (71)
  • July 2025 (89)
  • June 2025 (78)
  • May 2025 (95)
  • April 2025 (85)
  • March 2025 (78)
  • February 2025 (31)
  • January 2025 (50)
  • December 2024 (39)
  • November 2024 (42)
  • October 2024 (54)
  • September 2024 (83)
  • August 2024 (2665)
  • July 2024 (3210)
  • June 2024 (2908)
  • May 2024 (3025)
  • April 2024 (3132)
  • March 2024 (3115)
  • February 2024 (2893)
  • January 2024 (3169)
  • December 2023 (3031)
  • November 2023 (3021)
  • October 2023 (2352)
  • September 2023 (1900)
  • August 2023 (2009)
  • July 2023 (1878)
  • June 2023 (1594)
  • May 2023 (1716)
  • April 2023 (1657)
  • March 2023 (1737)
  • February 2023 (1597)
  • January 2023 (1574)
  • December 2022 (1543)
  • November 2022 (1684)
  • October 2022 (1617)
  • September 2022 (1310)
  • August 2022 (1676)
  • July 2022 (1375)
  • June 2022 (1458)
  • May 2022 (1297)
  • April 2022 (1464)
  • March 2022 (1491)
  • February 2022 (1249)
  • January 2022 (1282)
  • December 2021 (1663)
  • November 2021 (3139)
  • October 2021 (3253)
  • September 2021 (3136)
  • August 2021 (732)
Powered by Blogger.