CERT-UA Warns of New Vermin-Linked Phishing Attacks with PoW Bait

The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning about new phishing attacks designed to infect devices with malware. These attacks have been attributed to a threat group tracked by CERT-UA as UAC-0020, also known as Vermin. The full extent of the attacks remains unclear.

The attack begins with phishing emails that feature photos of purported prisoners of war (PoWs) from the Kursk region, enticing recipients to click on a link that leads to a ZIP archive.

Inside the ZIP file is a Microsoft Compiled HTML Help (CHM) file containing JavaScript code, which triggers an obfuscated PowerShell script when opened.

CERT-UA explained that opening the file installs components of the known spyware SPECTR, along with a new malware called FIRMACHAGENT. FIRMACHAGENT is designed to retrieve data stolen by SPECTR and transmit it to a remote server.

SPECTR, which has been linked to Vermin since 2019, is believed to be associated with security agencies of the Luhansk People’s Republic (LPR). In June, CERT-UA highlighted another campaign by the Vermin group, named SickSync, which targeted the country’s defense forces with SPECTR.

SPECTR is a powerful tool capable of stealing a wide range of information, including files, screenshots, credentials, and data from instant messaging apps like Element, Signal, Skype, and Telegram.


Please enter your comment!
Please enter your name here

Latest Articles

Sign Up for CXO Digital Pulse Newsletters

Sign Up for CXO Digital Pulse Newsletters to Download the Research Report

Sign Up for CXO Digital Pulse Newsletters to Download the Coffee Table Book

Sign Up for CXO Digital Pulse Newsletters to Download the Vision 2023 Research Report

Download 8 Key Insights for Manufacturing for 2023 Report

Sign Up for CISO Handbook 2023

Download India’s Cybersecurity Outlook 2023 Report

Unlock Exclusive Insights: Access the article

Download CIO VISION 2024 Report

Share your details to download the report

Share your details to download the CISO Handbook 2024

Enable Notifications OK No thanks