UAC-0245 CABINETRAT delivery campaign targeting Ukraine
Campaign
Summary
Hide ▲
Show ▼
A UAC-0245 campaign is using the CABINETRAT backdoor to target Ukraine, creating persistent access for reconnaissance and file transfer. The operation matters because the malicious XLL files are being delivered inside ZIP archives shared on Signal, increasing the chance of stealthy execution. Observed in September 2025, the activity combines a social-engineering lure with post-compromise tooling and anti-analysis checks. The delivery chain shows a coordinated intrusion operation rather than isolated malware use.
Related Happenings
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
Campaign
H score30
First: 23.04.2026 12:04
Last: 23.04.2026 12:04
Sources 1
About this happening:
The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
GopherWhisper China-aligned APT campaign targeting Mongolian government institutions
CampaignAbout this happening: The GopherWhisper campaign is a China-aligned APT operation targeting Mongolian governmental institutions, and it now appears to extend beyond a single compromise to *...
SloppyLemming spear-phishing campaign targeting Pakistan and Bangladesh
Campaign
H score37
First: 03.03.2026 08:53
Last: 03.03.2026 08:53
Sources 1
About this happening:
The SloppyLemming campaign is using spear-phishing, PDF lures, and macro-enabled Excel documents to target government entities and critical infrastructure operat...
SloppyLemming spear-phishing campaign targeting Pakistan and Bangladesh
CampaignAbout this happening: The SloppyLemming campaign is using spear-phishing, PDF lures, and macro-enabled Excel documents to target government entities and critical infrastructure operat...
SloppyLemming BurrowShell and Rust-based keylogger activity
Malware Activity
H score26
First: 03.03.2026 08:53
Last: 03.03.2026 08:53
Sources 1
About this happening:
SloppyLemming deployed BurrowShell and a Rust-based keylogger through two attack chains, expanding its malware toolkit for backdoor access, credential theft*...
SloppyLemming BurrowShell and Rust-based keylogger activity
Malware ActivityAbout this happening: SloppyLemming deployed BurrowShell and a Rust-based keylogger through two attack chains, expanding its malware toolkit for backdoor access, credential theft*...
Mustang Panda PlugX DOPLUGS deployment chain for persistent access
Malware Activity
H score26
First: 04.02.2026 16:09
Last: 04.02.2026 16:09
Sources 1
About this happening:
Mustang Panda (TA416) used malicious ZIP/LNK chains to deliver its custom PlugX/DOPLUGS payload and maintain persistent access on compromised hosts. The activity t...
Mustang Panda PlugX DOPLUGS deployment chain for persistent access
Malware ActivityAbout this happening: Mustang Panda (TA416) used malicious ZIP/LNK chains to deliver its custom PlugX/DOPLUGS payload and maintain persistent access on compromised hosts. The activity t...
DCRat delivered through PowerShell and MSBuild in PHALT#BLYX
Malware Activity
H score23
First: 06.01.2026 14:13
Last: 06.01.2026 14:13
Sources 1
About this happening:
SHADOW#REACTOR is a multi-stage Windows malware campaign that uses obfuscated VBS, PowerShell, wscript.exe, MSBuild.exe, and in-memory loaders to stealthil...
DCRat delivered through PowerShell and MSBuild in PHALT#BLYX
Malware ActivityAbout this happening: SHADOW#REACTOR is a multi-stage Windows malware campaign that uses obfuscated VBS, PowerShell, wscript.exe, MSBuild.exe, and in-memory loaders to stealthil...
Timeline
-
01.10.2025 10:11 2 articles · 9mo ago
CERT-UA warns of CABINETRAT attacks in Ukraine
Initial DisclosureCERT-UA warned of new targeted cyber attacks in Ukraine using the CABINETRAT backdoor, saying it found XLL add-ins delivered in ZIP archives via Signal and disguised as border-detention documents, and attributing the activity observed in September 2025 to UAC-0245.
Show sources
- Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs — thehackernews.com — 01.10.2025 10:11
- Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs — thehackernews.com — 01.10.2025 10:11