ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CERT-UA Warns of UAC-0173 Attacks Deploying DCRat to Compromise Ukrainian Notaries

mediumMalwareimportance 35CVE-2024-38213

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38213
Mark of the Web Security Feature Bypass in Microsoft Windows (CVE-2024-38213)

CVE-2024-38213 is a security feature bypass in the Windows Mark of the Web (MotW) mechanism that underpins SmartScreen warnings, allowing a maliciously crafted file to bypass the usual 'file downloaded from the internet' prompt. It is triggered when a user opens attacker-supplied content that defeats or strips the MotW flag, meaning the exploit requires user interaction (CVSS UI:R) and a network-accessible delivery vector such as email or a web download. On its own the flaw grants no confidentiality or availability impact but high integrity impact (CVSS 3.1 score 6.5), and in practice it is used to evade SmartScreen protections, typically chained with other bugs to achieve fuller compromise. It affects an extremely broad population: Windows 10 (1507 through 22H2), Windows 11 (21H2 through 23H2), and Windows Server 2012 through 2022. The flaw was one of six zero-days under active attack in Microsoft's August 2024 Patch Tuesday release and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-08-13; EPSS puts its 30-day exploitation probability at 13.6% (96th percentile).

Do: Apply the August 2024 Microsoft security updates (Patch Tuesday, released 2024-08-13) for every affected Windows 10, Windows 11, and Windows Server version, per CISA's KEV required action; treat this as a priority patch given confirmed in-the-wild exploitation. Because the bypass requires a user to open attacker-supplied content, reinforce caution around emailed and downloaded files until patching is complete, and confirm from vendor guidance whether any interim mitigations apply in environments that cannot patch immediately.

6.514% KEV
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2012, 2016, 2019, 2022
masshundreds of millions to billions of Windows desktop and server installations
Full article421 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 26, 2025Network Security / Threat Intelligence

The Computer Emergency Response Team of Ukraine (CERT-UA) on Tuesday warned of renewed activity from an organized criminal group it tracks as UAC-0173 that involves infecting computers with a remote access trojan named DCRat (aka DarkCrystal RAT).

The Ukrainian cybersecurity authority said it observed the latest attack wave starting in mid-January 2025. The activity is designed to target the Notary of Ukraine.

The infection chain leverages phishing emails that claim to be sent on behalf of the Ministry of Justice of Ukraine, urging recipients to download an executable, which, when launched, leads to the deployment of the DCRat malware. The binary is hosted in Cloudflare's R2 cloud storage service.

"Having thus provided primary access to the notary's automated workplace, the attackers take measures to install additional tools, in particular, RDPWRAPPER, which implements the functionality of parallel RDP sessions, which, in combination with the use of the BORE utility, allows you to establish RDP connections from the Internet directly to the computer," CERT-UA said.

The attacks are also characterized by the use of other tools and malware families like FIDDLER for intercepting authentication data entered in the web interface of state registers, NMAP for network scanning, and XWorm for stealing sensitive data, such as credentials and clipboard content.

Furthermore, the compromised systems are used as a conduit to draft and send malicious emails using the SENDMAIL console utility in order to further propagate the attacks.

The development comes days after CERT-UA attributed a sub-cluster within the Sandworm hacking group (aka APT44, Seashell Blizzard, and UAC-0002) to the exploitation of a now-patched security flaw in Microsoft Windows (CVE-2024-38213, CVSS score: 6.5) in the second half of 2024 via booby-trapped documents.

The attack chains have been found to execute PowerShell commands responsible for displaying a decoy file, while simultaneously launching additional payloads in the background, including SECONDBEST (aka EMPIREPAST), SPARK, and a Golang loader named CROOKBAG.

The activity, attributed to UAC-0212, targeted supplier companies from Serbia, the Czech Republic, and Ukraine between July 2024 and February 2025, with some of them recorded against more than two dozen Ukrainian enterprises specializing in development of automated process control systems (ACST), electrical works, and freight transportation.

Some of these attacks have been documented by StrikeReady Labs and Microsoft, the latter of which is tracking the threat group under the moniker BadPilot.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/cert-ua-warns-of-uac-0173-attacks.html