Ukraine's CERT-UA has identified a new cyber attack campaign using CABINETRAT backdoor malware. The threat actor UAC-0245 distributes malicious Excel add-in files (XLL) through Signal messaging app, disguised as border detention documents. Once executed, the malware establishes persistence, evades detection through anti-VM techniques, and provides full backdoor capabilities including system reconnaissance, file manipulation, and data exfiltration over TCP connections.
319 Impressions