Cybersecurity researchers have discovered targeted attacks against Ukrainethat exploit a Microsoft Office vulnerability to deliver Cobalt Strike to compromised systems. It is worth noting that this is a vulnerability that is about seven years old.

According to Deep Instinct, the attacks began in late 2023. The attack began with a PowerPoint slideshow file (“signal-2023-12-20-160512.ppsx”), with the filename suggesting it may have been shared via the instant messaging app Signal. However, there is no other evidence to suggest the file was distributed this way, although the Computer Emergency Response Team of Ukraine (CERT-UA) has uncovered two past campaigns that have used the Signal app to deliver malware.
Just last week, the agency revealed that the Ukrainian armed forces are increasingly being targeted by the UAC-0184 via messaging platforms and dating apps, to deliver malware such as HijackLoader, XWorm, and Remcos RAT.
See also: Linux malware AcidPour targets Ukraine
“The PPSX (PowerPoint slideshow) file appears to be an old US Army instruction manual,” said security researcher Ivan Kosarev. “The PPSX file contains a remote OLE external object.” This involves exploiting the CVE-2017-8570, an Office vulnerability that has been patched. However, on still-vulnerable systems, it could allow malicious actions to be performedafter the victim is convinced to open a specially crafted file to load a remote script hosted on weavesilk[.]space.
The script launches an HTML file containing JavaScript code, which, in turn, ensures persistence on the host computer via the Windows Registry and installs a next-stage payload that impersonates the Cisco AnyConnect VPN client.
The payload includes a dynamic-link library (DLL) that ultimately inserts a cracked Cobalt Strike Beacon directly into the system and awaits further instructions from a command-and-control (C2) server “petapixel[.]fun”).
At this time, attacks using the old Microsoft Office vulnerability cannot be attributed to a specific group. The ultimate goal of these attacks is also unknown.
See also: Operation Texonto: Russian hackers target Ukrainians with emails about the war
“The lure contained military content, suggesting it was targeting military personnel,” Kosarev said. “But the domain names weavesilk[.]space and petapixel[.]fun are related to an obscure generative art site (weavesilk[.]com) and a popular porn site (petapixel[.]com). They are not related to each other, and it’s a bit confusing why an attacker would use them specifically to trick military personnel.”

To avoid this Microsoft Office vulnerability, which allows the above attacks, organizations and system administrators should ensure that all available security updates are applied. Microsoft regularly releases updates to fix vulnerabilities found in its products.
Additionally, users should be cautious about the messages and attachments they receive, especially if they come from unknown senders. Many cybersecurity attacks begin with seemingly harmless emails that contain malware.
It is also important to use state-of-the-art security solutions, such as antivirus and intrusion detection and prevention systems (IDS/IPS), that can detect and block attack attempts.
See also: Ukraine: PurpleFox malware has infected 2000 computers
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Finally, educating users about cybersecurity threats and good security practices is crucial. Users who know how to recognize and deal with threats can prevent many attacks.
Sandworm hackers target critical infrastructure in Ukraine
The revelation comes as CERT-UA revealed that around 20 energy, water and heating suppliers in Ukraine have been targeted by a Russian state-run group called UAC-0133, a subgroup of Sandworm.
Source: thehackernews.com
