The Ukrainian Computer Emergency Response Team (CERT–UA) acting under SSSCIP warns of a new cyberattack by the UAC-0010 (Armageddon) group, associated with the Russian FSB.
See also: Battle.net recovers from DDoS attacks after one hour

Hackers are sending dangerous emails titled “Щодо проведение акция помсти у Херсоні!” (Ukrainian translation “Re: Revenge in Kherson!”), which contains an attached file “План Херсон.htm” (“Kherson Plan.htm”).
If opened, it creates a file “Herson.rar” on the computer with a shortcut “Plan of approach and installation of explosives at critical infrastructure facilities of Kherson.lnk”. What does this mean? “Plan of approach and installation of explosives at critical infrastructure facilities of Kherson.lnk”.
See also: Nerbian RAT: New malware distributed via COVID-19-themed emails
As a result, the GammaLoad.PS1v2 malware is downloaded (the mechanism for taking a screenshot and sending it to the management server has been implemented).

The hacking group UAC–0010 (Armageddon) is one of those that has been particularly active in attacking Ukraine’s critical information infrastructure since the beginning of the full-scale Russian military invasion of the country. The hackers use very sensitive topics for Ukrainians in their cyberattacks. The same group was found to have attacked EU
See also: HP patches two high-severity vulnerabilities
See details at: https://cert.gov.ua/article/40240 (UA)
