UAC-0057 Keeps Pressure on Ukraine and Poland
TLP:white
AlienVault
This report details recent cyber espionage campaigns targeting Ukraine and Poland, likely conducted by UAC-0057 (also known as UNC1151 or Ghostwriter). The threat actor used weaponized XLS spreadsheets with obfuscated VBA macros to drop first-stage DLL downloaders. C# and C++ downloaders were used to collect system information and retrieve next-stage payloads. The infrastructure leveraged domains impersonating legitimate websites, with consistent setups across campaigns. Notable evolutions include the use of Slack for command and control in some instances. The campaigns maintained disciplined targeting of Ukrainian and Polish organizations, consistent with UAC-0057's historical focus.
ukraine
confuserex
cobalt strike
poland
cyber espionage
+4 more
FileHash-MD5 23
FileHash-SHA1 23
FileHash-SHA256 25
CVE 1
YARA 2
domain 11
hostname 1
Created: Aug 27, 2025 7:54 PM
Updated: Aug 27, 2025 7:56 PM