The Latest Cyberthreat to Ukraine: HOMESTEEL Malware

Published:

spot_img

Recent Cyber Campaign Targeting Critical Ukrainian Data Repositories: Malware Variant HOMESTEEL by Threat Actor UAC-0218

A recent cyber campaign by the threat actor tracked as UAC-0218 has raised alarms in Ukraine, as a new malware variant named HOMESTEEL targets critical data repositories in the country. Ukraine’s Computer Emergency Response Team (CERT-UA) flagged this offensive, signaling a familiar tactic used by adversaries to steal sensitive information from government and business networks.

The phishing methods employed in this campaign involve emails with subject lines like “account” and “details,” leading recipients to a deceptive “eDisk” platform link. Upon clicking, users unwittingly download RAR files containing password-protected documents labeled as “Contract20102024.doc” and “Invoice20102024.xlsx.” A hidden Visual Basic Script file, “Password.vbe,” then triggers HOMESTEEL’s data extraction process.

HOMESTEEL goes beyond traditional malware by selectively targeting specific file types – such as xls, xlsx, doc, and pdf – within user directories. By utilizing HTTP PUT requests, the malware transfers extracted files under 10MB to an external server, evading detection while maximizing data collection.

Moreover, HOMESTEEL adapts to proxy settings on compromised systems, masking its network traffic and facilitating persistent surveillance. The malware relies on PowerShell commands to perform additional file reconnaissance, scouring directories for specific extensions and transferring files via HTTP POST requests for centralized storage.

The campaign’s infrastructure tactics link it to previous attacks back to August 2024, showcasing a pattern of using shared components and domain registrations for increased efficiency. As Ukraine continues to face evolving cyber threats, CERT-UA’s proactive monitoring of UAC-0218 highlights the importance of detecting and mitigating sophisticated malware campaigns like HOMESTEEL.

spot_img

Related articles

Recent articles

Massive Data Breach Affects 8.4 Million Users of Indian Ridesharing Company

Major Data Breach Affects 8.4 Million Users of Indian Ridesharing Company ZoomCar's Cybersecurity Incident In a significant cybersecurity breach, an unauthorized user has gained access to...

UAE Unveils Emergency Airport Plan to Address Travel Disruptions

UAE Activates Emergency Business Continuity Plan for Airports The United Arab Emirates (UAE) has initiated its emergency business continuity plan to ensure the ongoing operation...

Are Neglected AD Service Accounts Putting You at Risk?

### Understanding Active Directory Service Accounts For numerous organizations, Active Directory (AD) service accounts often become neglected remnants of past projects. Originally created for specific...

2024 AT&T Data Breach Records Resurface for Sale on the Dark Web

Reemergence of AT&T Customer Data on the Dark Web Overview of the Incident In a concerning turn of events, nearly 90 million AT&T customer records, including...