Latest adversary campaign impersonates Ukrainian security agency to deliver Remcos spyware

Latest adversary campaign impersonates Ukrainian security agency to deliver Remcos spyware

Ukraine’s CERT team has shared technical details and Indicators of Compromise (IoCs) associated with a new phishing campaign that impersonates the Security Service of Ukraine (SBU) to deploy remote access software onto target systems.

The attacks start from a phishing email containing a RAR archive named “Електронна вимога СБУ України.rar” (“The digital requirement of the SBU”) that includes another similarly named archive. Once opened, this archive leads to the installation of the Remcos remote access trojan (RAT) on the victim’s system.

CERT-UA has attributed this malicious activity to a threat actor it tracks as UAC-0050.

Earlier this month, cybersecurity company Mandiant published details of a previously unreported campaign by the Russia-linked threat actor Sandworm that targeted one of the power plants in Ukraine.

In October, Ukraine’s CERT revealed that at least 11 telecommunications service providers in Ukraine have been hit with destructive Sandworm attacks between May and September 2023.

Additionally, Ukraine's National Cyber Security Coordination Center (NCSСС) warned that suspected Russian cybercrime groups have been increasingly targeting state and financial institutions in Ukraine with the SmokeLoader malware.


Back to the list

Latest Posts

Cyber Security Week in Review: June 13, 2025

Cyber Security Week in Review: June 13, 2025

In brief: Microsoft fixes zero-day exploited by the Stealth Falcon APT, the Graphite spyware targets journalists via an iMessage exploit, and more.
13 June 2025
Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

Coordinated brute-force campaign targets Apache Tomcat Manager interfaces

The campaign, first observed on June 5, involves brute-force login attempts originating from hundreds of unique IP addresses.
12 June 2025
ConnectWise rotates digital certificates due to security risks

ConnectWise rotates digital certificates due to security risks

The company said that this is a preventive action and not related to any recent security incident.
11 June 2025