Russian group UAC-0194 targets Ukraine using phishing and CVE-2024-43451 exploitation.
Analyst brief
UAC-0194 is a Russian threat actor primarily targeting Ukrainian organizations. The group leverages phishing emails containing .url files to exploit the CVE-2024-43451 zero-day vulnerability, deploying payloads such as the SparkRAT trojan and exfiltrating NTLM hashes via the SMB protocol. Defenders should monitor for .url-based email attachments, anomalous NTLM authentication attempts, and SparkRAT-related C2 indicators, while ensuring user awareness against social engineering tactics.
UAC-0194
unknown
UAC-0194 is a Russian threat actor linked to the exploitation of the Windows zero-day CVE-2024-43451, which was used in attacks against Ukrainian organizations. The group delivered phishing emails containing .url files that, when interacted with, exploited the vulnerability to facilitate the installation of additional payloads, including the SparkRAT trojan. They also exploited the Server Message Block protocol for NTLM hash exfiltration. CERT-UA has associated UAC-0194's activities with social engineering tactics to convince victims to execute malicious files.
What vulnerability does UAC-0194 exploit to gain access to its targets?+
UAC-0194 primarily exploits the CVE-2024-43451 vulnerability to gain access to its targets. This zero-day is triggered through phishing emails containing .url files.
Through which protocol does UAC-0194 exfiltrate NTLM hashes?+
UAC-0194 exfiltrates NTLM hashes via the SMB (Server Message Block) protocol.