According to the Computer Emergency Response Team (CERT) of Ukraine, Russian hackers are exploiting the Follina vulnerability in phishing attacksto install CredoMap malware and Cobalt Strike beacons.

The attacks distributing the CredoMap malwareby the Russian hacking group APT28, which is said to be sending phishing emails containing a malicious document named “Nuclear Terrorism A Very Real Threat.rtf.” Apparently, the Russian hackers have chosen this subject for the phishing emails to increase the chances of the malicious document being opened, taking advantage of the fear in Ukraine of a possible nuclear attack.
See also: Cyberattack disrupts services of parcel company Yodel
Similar attacks have occurred in the past. In May 2022, CERT-UA detected the distribution of malicious documents warning of a chemical.
The malicious document in the phishing emails sent by Russian hackers is an RTF document that attempts to exploit the CVE-2022-30190 vulnerability, also known as “Follina”, to download and launch the CredoMap malware (docx.exe) on a target’s device.
This is a vulnerability in the Microsoft Diagnostic Tool, used by cybercriminals since at least April 2022, triggering malicious downloads by simply opening a document or, in the case of RTF, simply viewing it in the Windows preview window.
CredoMap is an unknown malware detected by multiple AV engines at Virus Total, with many vendors classifying it as Trojan password-stealing

In a related report published by Malwarebytes, it is clarified that the malicious payload is an info-stealer that APT28 used against Ukrainian targets in May. The malware aims to steal information stored in Chrome, Edge, and Firefox browsers.
See also: Adobe Acrobat: Does it prevent antivirus tools from tracking PDF files?
After the theft, the malware sends the stolen data to the criminals.
According to MalwareHunterteam, which discovered this campaign, the malware uses hard-coded IMAP credentials, potentially allowing any researcher to access the stolen data.
Ukraine’s CERT warned last week that Russian hackers were using the Follina vulnerability against targets in the country, but this time it was linked to the Russian hacking group APT28. APT28 (also known as STRONTIUM, Fancy Bear, and Sofacy) focuses on cyber espionage and is believed to have ties to the Russian government. The group has been active since 2007, targeting governments, the military, and security agencies.
Cobalt Strike
Alongside the above activity, CERT-UA also detected a different campaign from a threat actor tracked as UAC-0098. According to experts, these attackers are also using CVE-2022-30190 to infect the target.
In this case, CERT-UA says the threat actor uses a DOCX file named “Imposition of penalties.docx” and the payload is a Cobalt Strike beacon (ked.dll).

The emails sent purport to come from the State Tax Service of Ukraine, with the subject line: “Notice of non-payment of tax.”
See also: Icefall: 56 flaws affect exposed industrial devices
Given that Ukraine is at war with Russia and many citizens have neglected their tax obligations to the state, many can fall into the trap.
The Computer Emergency Response Team (CERT) of Ukraine advises employees in critical organizations to be very careful with the emails they receive, as in most cases, attacks begin with phishing messages.
Source: www.bleepingcomputer.com
