UAC-0154 targets Ukraine's military with the STARK#VORTEX phishing campaign delivering MerlinAgent RAT.
Analyst brief
UAC-0154 is a threat actor running the STARK#VORTEX phishing campaign, specifically targeting Ukraine's military personnel. They use Microsoft Help files disguised as drone manuals, containing obfuscated JavaScript, to deliver the MerlinAgent RAT via emails to @ukr.net addresses. This heavily obfuscated, PowerShell-based malware downloads a payload from a remote server to gain full control over compromised systems. Defenders should focus on blocking suspicious .chm attachments, restricting PowerShell execution policies, and monitoring for unusual outbound C2 connections.
UAC-0154
unknown
UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military. They employ a Microsoft Help file containing obfuscated JavaScript as a lure, disguised as a manual for Pilot-in-Command Drones, to deliver the MerlinAgent malware. This PowerShell-based RAT is heavily obfuscated and downloads a payload from a remote server, enabling full control over compromised systems. The group initially targeted Ukrainian entities using military-themed documents sent via email to @ukr.net addresses.