Phishing Campaign Targets Ukrainian Military Entities

russia ukraine cyberattacks

Ukrainian military organizations have become the focal point of a phishing campaign that exploits drone manuals to deliver a Go-based open-source post-exploitation toolkit named Merlin.

Securonix researchers Den Iuzvyk, Tim Peck, and Oleg Kolesnikov reported in a document shared with The Hacker News that because drones, also known as Unmanned Aerial Vehicles (UAVs), have become an essential tool in the Ukrainian military's arsenal, cybercriminals have begun circulating malicious lure files disguised as UAV service manuals.

Initial Stage Payload Hidden in Help Files

This campaign, which goes by the name STARK#VORTEX and is being monitored by the cybersecurity company, kicks off with a Microsoft Compiled HTML Help (CHM) file. Once this file is opened, it activates malicious JavaScript embedded within one of the HTML pages, triggering PowerShell code. This PowerShell code is designed to establish contact with a remote server to retrieve an obfuscated binary.

After decoding, the Windows-based payload reveals the Merlin Agent, which is then configured to establish communication with a command-and-control (C2) server. This enables the cybercriminals to take control of the compromised host and execute post-exploitation actions.

The researchers noted that although the attack chain appears relatively straightforward, the attackers have employed intricate Tactics, Techniques, and Procedures (TTPs) and obfuscation methods to evade detection.

This marks the first instance in which Ukrainian government entities have been targeted using the Merlin toolkit. In early August 2023, the Computer Emergency Response Team of Ukraine (CERT-UA) disclosed a similar attack chain that used CHM files as decoys to infect computers with this open-source tool. CERT-UA attributed these intrusions to a threat actor it tracks under the name UAC-0154.

The researchers emphasized that the files and documents employed in this attack chain possess the capability to bypass security defenses. They noted that while it may seem unusual to receive a Microsoft help file via the internet, the attackers have framed these lure documents to resemble something an unsuspecting victim might expect to encounter in a help-themed document or file.

September 25, 2023
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.