The Computer Emergency Response Team of Ukraine has issued a warning about cyber attacks against state authorities in the country that use a legitimate remote access software called Remcos. The malicious campaign is believed to be conducted by a threat actor known as UAC-0050, and is likely motivated by espionage. The attack begins with phishing emails that appear to be from Ukrainian telecom company Ukrtelecom and contain a decoy RAR archive. This archive contains two files, one of which is a password-protected RAR file that is over 600MB in size, and the other is a text file with the password to open the RAR file. Inside the second RAR archive is an executable that installs the Remcos remote access software, giving the attacker full control of the compromised computer. Remcos is a remote control and surveillance software offered by Breaking Security, and can be purchased for a fee ranging from €58 to €945. It is described as a lightweight, fast and highly customizable tool with a variety of features. The CERT-UA advisory comes after the State Cyber Protection Centre of Ukraine identified a Russian state-sponsored threat actor called Gamaredon that is targeting public authorities and critical information infrastructure.
This Cyber News was published on thehackernews.com. Publication date: Wed, 08 Feb 2023 09:55:03 +0000