Ukraine's CERT-UA has identified a new cyber attack campaign using CABINETRAT backdoor malware. The threat actor UAC-0245 distributes malicious Excel add-in files (XLL) through Signal messaging app, disguised as border detention documents. Once executed, the malware establishes persistence, evades detection through anti-VM techniques, and provides full backdoor capabilities including system reconnaissance, file manipulation, and data exfiltration over TCP connections.

2m read timeFrom thehackernews.com
Post cover image
319 Impressions