HomeSecurityUAC-0125 hackers abuse Cloudflare Workers to distribute malware

UAC-0125 hackers abuse Cloudflare Workers to distribute malware

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed that a group of hackers (tracked as UAC-0125) is abusing the Cloudflare Workers service to trick military personnel in the country into downloading malware disguised as the Army+ app, a mobile application introduced by the Ministry of Defense in August.

Cloudflare Workers hackers UAC-0125 malware Army+ app

Users who visit the fake Cloudflare Workers websites are prompted to download an Army+ Windows executable, which is created via the NullsoftScriptable Install System (NSIS).

See also: Hackers exploit Webview2 to deliver CoinLurker malware

Opening the malicious binary displays a decoy file, while simultaneously executing a PowerShell script. This, in turn, installs OpenSSH on the infected computer, generates an RSA cryptographic key pair, adds the public key to the “authorized_keys” file, and transmits the private key to a server controlled by the UAC-0125 hackers.

According to CERT-UA, the hackers' goal is to gain remote access to the victim's machine. At this time, we do not know how the UAC-0125 hackers distribute the fake links for Cloudflare Workers.

CERT-UA noted that these hackers are associated with another group, UAC-0002, which is better known as APT44, FROZENBARENTS, Sandworm, Seashell Blizzard, and Voodoo Bear. This group is linked to Russia.

See also: Malicious SharePoint notifications distribute Xloader Malware

Earlier this month, Fortra revealed that it has observed an “upward trend in abuse of legitimate services,” with attackers using Cloudflare Workers and Pages to host fake Microsoft 365 login pages and steal user credentials.

Considering these recent attacks on Ukrainian military personnel, we understand that organizations across all industries need to be aware of the potential risks posed by malicious actors and take steps to protect themselves. With the increasing reliance on technology, it has become critical to prioritize cybersecurity measures.

UAC-0125 hackers abuse Cloudflare Workers to distribute malware

One way to strengthen defenses against such attacks is through regular employee education and awareness programs. By educating individuals about common types of cyber threats and how to spot them, organizations can reduce the chances of falling victim to such attacks.

See also: Hackers use Yokai Malware

Additionally, implementing strong security protocols and regularly updating software can also help mitigate the risk of cyberattacks. It is important for organizations to constantly monitor their networks and systems for any suspicious activity or anomalies.

Finally, staff should be cautious with messages or emails containing links and should only download applications and software from trusted and official pages.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS