Реклама партнера — Название партнёра
UNIT.City — місце, де люди працюють... КРАЩЕ! Обирай свій простір просто зараз 👉

Malicious XLL files in Signal: State Special Communications Service warns representatives of the Defense Forces about a new cyber threat

The Cyber ​​Command of the State Special Communications Service CERT-UA has discovered new targeted cyberattacks on representatives of the Defense Forces of Ukraine. The main goal is to install a fully functional CABINETRAT backdoor to gain remote control over the affected system.

Leave a comment
Malicious XLL files in Signal: State Special Communications Service warns representatives of the Defense Forces about a new cyber threat

The Cyber ​​Command of the State Special Communications Service CERT-UA has discovered new targeted cyberattacks on representatives of the Defense Forces of Ukraine. The main goal is to install a fully functional CABINETRAT backdoor to gain remote control over the affected system.

The attackers, known as UAC-0245, are attacking computers using malicious XLL files that impersonate important documents, such as "UBD Request.xll" or border protocols. These files are distributed, in particular, through the Signal messenger, the State Special Communications Service reports .

An attack via XLL files is more dangerous than via typical Word documents because these files are executable programs.

When a user opens such a file in Excel, a multi-stage infection process is activated: auxiliary files are created, including an executable launcher file (runner.exe) and an XLL add-in (loader.xll), which is placed in the Excel startup folder. Fixation in the system is carried out through entries in the system registry and settings of scheduled tasks.

"The ultimate goal of this chain is to launch a hidden Excel process, which automatically loads loader.xll. This file, in turn, reads and executes the main malicious component hidden in a regular PNG image. This shellcode is the CABINETRAT backdoor," cyber experts explain.

"Social engineering is more dangerous than DDoS": Mykhailo Fedorov told where cyberattacks on the Ministry of Digital Economy are aimed
"Social engineering is more dangerous than DDoS": Mykhailo Fedorov told where cyberattacks on the Ministry of Digital Economy are aimed
On the topic
"Social engineering is more dangerous than DDoS": Mykhailo Fedorov told where cyberattacks on the Ministry of Digital Economy are aimed
GUR cyber specialists paralyzed the Russian "SBP" and disrupted online payments and transfers
GUR cyber specialists paralyzed the Russian "SBP" and disrupted online payments and transfers
On the topic
GUR cyber specialists paralyzed the Russian "SBP" and disrupted online payments and transfers
Major European airports hit by massive cyberattack
Major European airports hit by massive cyberattack
On the topic
Major European airports hit by massive cyberattack
The US and Europol are looking for a hacker from Ukraine who organized cyberattacks on several hundred companies around the world. They are ready to pay millions of dollars for information that will help find him
The US and Europol are looking for a hacker from Ukraine who organized cyberattacks on several hundred companies around the world. They are ready to pay millions of dollars for information that will help find him
On the topic
The US and Europol are looking for a hacker from Ukraine who organized cyberattacks on several hundred companies around the world. They are ready to pay millions of dollars for information that will help find him
Read the country's main IT news in our Telegram
Read the country's main IT news in our Telegram
On the topic
Read the country's main IT news in our Telegram

Have important news to share? Message our Telegram bot

Key events and useful links in our Telegram channel

Discussion
No comments yet.