Ukrainian Firms Under Attack: WinRAR Exploit Unleashes LONEPAGE Malware

1 min read
Source: The Hacker News
Ukrainian Firms Under Attack: WinRAR Exploit Unleashes LONEPAGE Malware
Photo: The Hacker News
TL;DR Summary

The threat actor UAC-0099 has been targeting Ukrainian firms using a high-severity vulnerability in WinRAR to distribute the LONEPAGE malware. The attacks involve phishing messages with HTA, RAR, and LNK file attachments, leading to the deployment of LONEPAGE, a VBS malware capable of retrieving additional payloads. UAC-0099 has gained unauthorized remote access to several dozen computers in Ukraine. The group also utilizes self-extracting archives and ZIP files to exploit the WinRAR vulnerability. The attacks rely on PowerShell and the creation of a scheduled task to execute a VBS file. Additionally, CERT-UA has warned of a new wave of phishing messages attributed to UAC-0050, spreading the Remcos RAT.

Share this article

Reading Insights

Total Reads

0

Unique Readers

1

Time Saved

2 min

vs 3 min read

Condensed

74%

409107 words

Want the full story? Read the original article

Read on The Hacker News