EXECUTIVE SUMMARY
A significant increase in the activity of the UAC-0057 group has been recorded, highlighting a targeted campaign aimed at distributing malicious documents containing macros. These documents are intended to launch the PICASSOLOADER malware on the victim's computer, ultimately delivering the Cobalt Strike Beacon. The primary focus of this campaign appears to be entities involved in local self-government reform and related financial and economic activities in Ukraine.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
A significant increase in the activity of the UAC-0057 group has been recorded, highlighting a targeted campaign aimed at distributing malicious documents containing macros. These documents are intended to launch the PICASSOLOADER malware on the victim's computer, ultimately delivering the Cobalt Strike Beacon. The primary focus of this campaign appears to be entities involved in local self-government reform and related financial and economic activities in Ukraine.[emaillocker id="1283"]
The campaign utilizes various document files named "oborona.rar," "66_oborona_PURGED.xls," "trix.xls," "equipment_survey_regions_.xls," "accounts.xls," "spreadsheet.xls," "attachment.xls," and "Tax_2024.xls." These documents cover themes related to local self-government reform, the USAID/DAI "HOVERLA" project, taxation, and financial and economic indicators. Upon opening these documents, the embedded macros execute scripts that deploy the PICASSOLOADER malware. PICASSOLOADER acts as a delivery mechanism for the Cobalt Strike Beacon, which enables attackers to conduct further malicious activities, including command and control, lateral movement, and data exfiltration.
The observed campaign suggests that UAC-0057 is targeting individuals and entities involved in local self-government projects and financial sectors within Ukraine. The nature of the documents indicates a focus on project office specialists and their counterparts within local self-government bodies. It is crucial for individuals and organizations in these sectors to remain vigilant and any suspicious activity. It detects and can help mitigate the threat and protect against potential compromises.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Initial Access | T1566 | Phishing |
| Execution | T1203 | Exploitation for Client Execution |
| Defense Evasion | T1078 | Valid Accounts |
| Collection | T1213 | Data from Information Repositories |
| Command and Control | T1071 | Application Layer Protocol |
REFERENCES:
The following reports contain further technical details:
https://securityaffairs.com/166265/intelligence/belarus-apt-ghostwriter-targeted-ukraine.html