Latest adversary campaign impersonates Ukrainian security agency to deliver Remcos spyware

Latest adversary campaign impersonates Ukrainian security agency to deliver Remcos spyware

Ukraine’s CERT team has shared technical details and Indicators of Compromise (IoCs) associated with a new phishing campaign that impersonates the Security Service of Ukraine (SBU) to deploy remote access software onto target systems.

The attacks start from a phishing email containing a RAR archive named “Електронна вимога СБУ України.rar” (“The digital requirement of the SBU”) that includes another similarly named archive. Once opened, this archive leads to the installation of the Remcos remote access trojan (RAT) on the victim’s system.

CERT-UA has attributed this malicious activity to a threat actor it tracks as UAC-0050.

Earlier this month, cybersecurity company Mandiant published details of a previously unreported campaign by the Russia-linked threat actor Sandworm that targeted one of the power plants in Ukraine.

In October, Ukraine’s CERT revealed that at least 11 telecommunications service providers in Ukraine have been hit with destructive Sandworm attacks between May and September 2023.

Additionally, Ukraine's National Cyber Security Coordination Center (NCSСС) warned that suspected Russian cybercrime groups have been increasingly targeting state and financial institutions in Ukraine with the SmokeLoader malware.


Back to the list

Latest Posts

Cyber Security Week in Review: May 9, 2025

Cyber Security Week in Review: May 9, 2025

In brief: SAP zero-day exploited by Chinese hackers, SonicWall patches bugs in its SMA appliances, and more.
9 May 2025
Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

Russia-linked Coldriver hackers deploy new espionage malware in targeted attacks

LOSTKEYS is designed to steal sensitive files, harvest system information, and exfiltrate details about running processes.
8 May 2025
Russia-aligned operation manipulates audio and images to impersonate experts

Russia-aligned operation manipulates audio and images to impersonate experts

The operation primarily focused on undermining NATO support for Ukraine and spreading false narratives to disrupt domestic politics in EU member states.
7 May 2025