Threat Advisory

Belarus-linked APT GhostWriter Targets Ukraine with PICASSOLOADER Malware

Threat: Malware
Threat Actor Name: TA445
Threat Actor Type: State-Sponsored
Targeted Region: Ukraine
Alias: UNC1151, DEV-0257/Storm-0257, TA445, Moonscape, UAC-0057/UAC-0051/UAC-0105, Blue Dev 4, Ghostwriter, Pushcha
Threat Actor Region: Belarus
Targeted Sector: Government & Defense
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A significant increase in the activity of the UAC-0057 group has been recorded, highlighting a targeted campaign aimed at distributing malicious documents containing macros. These documents are intended to launch the PICASSOLOADER malware on the victim's computer, ultimately delivering the Cobalt Strike Beacon. The primary focus of this campaign appears to be entities involved in local self-government reform and related financial and economic activities in Ukraine.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY

A significant increase in the activity of the UAC-0057 group has been recorded, highlighting a targeted campaign aimed at distributing malicious documents containing macros. These documents are intended to launch the PICASSOLOADER malware on the victim's computer, ultimately delivering the Cobalt Strike Beacon. The primary focus of this campaign appears to be entities involved in local self-government reform and related financial and economic activities in Ukraine.[emaillocker id="1283"]

 

The campaign utilizes various document files named "oborona.rar," "66_oborona_PURGED.xls," "trix.xls," "equipment_survey_regions_.xls," "accounts.xls," "spreadsheet.xls," "attachment.xls," and "Tax_2024.xls." These documents cover themes related to local self-government reform, the USAID/DAI "HOVERLA" project, taxation, and financial and economic indicators. Upon opening these documents, the embedded macros execute scripts that deploy the PICASSOLOADER malware. PICASSOLOADER acts as a delivery mechanism for the Cobalt Strike Beacon, which enables attackers to conduct further malicious activities, including command and control, lateral movement, and data exfiltration.

 

The observed campaign suggests that UAC-0057 is targeting individuals and entities involved in local self-government projects and financial sectors within Ukraine. The nature of the documents indicates a focus on project office specialists and their counterparts within local self-government bodies. It is crucial for individuals and organizations in these sectors to remain vigilant and any suspicious activity. It detects and can help mitigate the threat and protect against potential compromises.

THREAT PROFILE:

Tactic Technique Id Technique
Initial Access  T1566 Phishing
Execution  T1203 Exploitation for Client Execution
Defense Evasion T1078 Valid Accounts
Collection T1213 Data from Information Repositories
Command and Control T1071 Application Layer Protocol

REFERENCES:

The following reports contain further technical details:
https://securityaffairs.com/166265/intelligence/belarus-apt-ghostwriter-targeted-ukraine.html

[/emaillocker]
crossmenu