A compromised email account belonging to the Ukrainian Ministry of Defense was detected sending phishing emails and instant messages targeting users of the military program “DELTA,” in an attempt to infiltrate their systems with info-stealing malware.
See also: T-Mobile: New SIM Protection feature released!

Today, CERT-UA (Computer Emergency Response Team of Ukraine) issued a warning to Ukrainian military personnel about the malicious malware attack, publishing an official report highlighting their campaign.
DELTA, created by Ukraine with the help of its allies, is a powerful intelligence collection and management system designed to help military personnel monitor the activities of their adversaries.
See also: CRM platform SevenRooms confirmed to have been hacked
The innovative system offers a full suite of real-time information, seamlessly connecting data from multiple sources into an interactive digital map that can run on any device – regardless of whether it is a laptop or smartphone.
Digital certificates are used to sign software code and authenticate servers, telling security products running on the operating system that the application has not been compromised and that the server operator is who they claim to be.
Infection process
This campaign used malicious emails or messages with fabricated warnings to convince users that they needed to update their “DELTA” certificates in order for their system to remain secure.
A malicious email has been circulating that contains a PDF document with misleading instructions to download a file named “certificates_rootCA.zip.” Be careful not to click on any links contained in the message, as they may lead to dangerous malware or viruses!


The file includes a digitally signed executable file, “certificates_rootCA.exe”, which creates various DLL files on the target user’s machine and launches “ais.exe”,
which simulates the certificate installation process.
This action leads the victim to believe that everything was authentic, significantly reducing the likelihood of them recognizing that they have been hacked.

Both EXE and DLL files are protected by VMProtect, a legitimate software used to wrap files in standalone virtualized machines, encrypting their contents and making them impossible to analyze or detect by AV.
The dropped DLLs, “FileInfo.dll” and “procsys.dll,” are malware, identified by CERT-UA as “FateGrab” and “StealDeal.”.
FateGrab is an FTP file stealer that targets documents and emails with the following file formats: '.txt', '.rtf', '.xls', '.xlsx', '.ods', '.cmd', '.pdf' , '.vbs', '.ps1', '.one', '.kdb', '.kdbx', '.doc', '.docx', '.odt', '.eml', '.msg' , 'email'.
See also: H-Hotels: Play ransomware responsible for cyberattack
StealDeal is an information stealer malware that can be used to obtain confidential information, such as web and passwords stored in web browsers.
After a thorough investigation, CERT-UA was unable to trace the business to any known malicious actors.

Info-stealing malware is an increasingly common form of malicious code that can be used to steal confidential information from unsuspecting victims’ computers and networks. While it’s impossible to completely prevent infections, there are steps you can take to protect yourself from falling victim to this type of attack. Make sure you’re using up-to-date antivirus software and regularly scanning your system for any suspicious activity. Additionally, make sure you never open suspicious email or links sent from unknown sources – these may contain information-stealing malware that can wreak havoc on your computer system if left unchecked!
Information source: bleepingcomputer.com
