Russia-linked threat actor UAC-0184 targeted Ukrainian military and government entities with a phishing campaign in 2025. The group used Viber messages to deliver malicious ZIP files as part of ongoing intelligence-gathering operations, with further coverage provided by Security Affairs.The UAC-0184 group, also known as Hive0156, launched a campaign against Ukraine's Verkhovna Rada, exploiting sensitive themes such as changes to military personnel files and denied compensation for fallen soldiers. The attack campaign uses Viber as the initial access vector, sending malicious ZIP archives disguised as official parliamentary documents. Once extracted, victims encounter deceptive LNK shortcuts that initiate a multi-step infection process. This process involves PowerShell scripts downloading further malicious files, using legitimate programs to load malware, and displaying fake documents to distract victims before installing HijackLoader and the Remcos RAT. The attackers aim to gain remote control, steal data, and execute commands.This campaign highlights the persistent threat posed by Russia-linked APT groups against Ukrainian government and military infrastructure. The use of popular messaging platforms like Viber and sophisticated evasion techniques underscores the need for enhanced cybersecurity awareness and robust security controls, including strong encryption and access management, to mitigate espionage risks.Source: Security Affairs
Malware, Threat Intelligence, Phishing
Russia-linked UAC-0184 targets Ukraine military and government via Viber with malicious ZIP files
(Image credit: opolja via Getty)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
