Skip to content
Breaking
Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech Latest technical intelligence from Northeast India • Infrastructure, AI, Cloud & Security Analysis • Precision Analysis | Raw Intelligence | Your North Star of Tech
SECURITY

Analysis: Russia-Aligned Hackers Abuse Viber to Target Ukrainian Military and Government

UAC-0184 Hackers Leverage Viber for Espionage: Implications for North East India

UAC-0184 Hackers Leverage Viber for Espionage: Implications for North East India

UAC-0184: A Persistent Threat

The Russia-aligned cyber threat actor UAC-0184, also known as Hive0156, has been persistently targeting Ukrainian military and government departments since early 2024. This group is primarily known for using war-themed lures in phishing emails to deliver malware, such as Hijack Loader and Remcos RAT.

Evolving Tactics

Recent findings by Chinese security vendors suggest that UAC-0184 has evolved its tactics, now leveraging the Viber messaging platform to deliver malicious ZIP archives. This marks a shift from previous methods that used Signal and Telegram for malware delivery.

The Attack Chain

The attack chain involves the use of Viber as an initial intrusion vector to distribute malicious ZIP archives containing Windows shortcut (LNK) files disguised as official Microsoft Word and Excel documents. These LNK files serve as a decoy to trick recipients into opening them, while silently executing Hijack Loader in the background.

A Sophisticated Attack

The attack reconstructs and deploys Hijack Loader in memory through a multi-stage process that employs techniques like DLL side-loading and module stomping to evade detection by security tools. The loader then scans the environment for installed security software and takes steps to subvert static signature detection before covertly executing Remcos RAT.

Implications for North East India

While the focus of UAC-0184's activities has been on Ukraine, the tactics used by this group could potentially be adapted to target entities in North East India. As with any cyber threat, it is crucial for organizations to stay vigilant and implement robust security measures to protect against such attacks.

Staying Secure

Organizations should educate their employees about phishing attempts and the potential risks of opening unexpected email attachments or clicking on suspicious links. Additionally, keeping software up-to-date and implementing multi-factor authentication can help mitigate the risks of such attacks.

Looking Forward

As cyber threats continue to evolve, it is essential for organizations to stay informed about the latest tactics and to adapt their security strategies accordingly. By staying vigilant and proactive, we can better protect ourselves against cyber espionage and data theft activities.