The APT group UAC-0063 leverages legitimate documents stolen from one victim to target another organization. In the most recent attacks, UAC-0063 hackers used this method to attack European embassies and deliver malware (e.g. HATVIBE).

“This investigation focuses on completing the picture regarding the activities of the UAC-0063 hackers. It particularly shows their expansion beyond their initial focus in Central Asia, targeting entities such as embassies in several European countries (e.g. Germany, the United Kingdom, the Netherlands, Romania, and Georgia), said Martin Zugec, technical solutions manager at Bitdefender.
See also: Hackers exploit vulnerabilities in SimpleHelp RMM
The UAC-0063 hackers were first reported by a Romanian cybersecurity firm in May 2023. At the time, they were targeting government entities in Central Asia with the DownEx data-stealing malware . There is a possible connection to the notorious Russian hacking group APT28.
A few weeks later, the Computer Emergency Response Team of Ukraine (CERT-UA) revealed that the group has been operating since at least 2021 and is attacking the country's state institutions with a keylogger (LOGPIE), an HTML Application script loader (HATVIBE malware), a Python backdoor (CHERRYSPY or DownExPyer), and DownEx.
There are indications that the UAC-0063 hackers have also targeted various government entities and educational organizations in Central Asia, East Asia, and Europe, according to Recorded Future's Insikt Group (which tracks the group under the name TAG-110).
The latest findings from Bitdefender show that the attacks continue with the distribution of DownEx, DownExPyer, and a new USB data exfiltrator codenamed PyPlunderPlug. At least one such attack has been detected on a German company in mid-January 2023.
See also: EU: Sanctions on Russian GRU hackers for attacks in Estonia
DownExPyer is equipped with a variety of capabilities to maintain a persistent connection to a remote server and receive commands to collect data, execute commands, and deploy additional malicious payloads.
Bitdefender said it also detected a Python script designed to record keystrokes – likely a precursor to LOGPIE – on one of the compromised computers that was infected with the DownEx, DownExPyer and HATVIBE malware.
“UAC-0063 hackers are a sophisticated threat group characterized by their advanced capabilities and persistent targeting of government entities,” said Zugec.
“The hackers' arsenal, combined with well-crafted TTPs, indicate a clear focus on espionage and intelligence gathering. Targeting government entities in specific regions aligns with potential Russian strategic interests“.
See also: Pwn2Own Automotive 2025: Hackers won $886,250

To combat these threats, security experts recommend a multi-layered approach that includes regular security audits, training employees on cybersecurity best practices , and implementing advanced threat detection and response tools. It is also important for organizations to regularly update their devices and software to protect against known vulnerabilities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another critical aspect of defending against APT attacks is enhancing collaboration between different departments within an organization. This includes promoting communication between security teams, IT departments, and executive leadership. By collaborating and sharing information, organizations can better identify potential risks and respond quickly to any suspicious activity.
Additionally, it is important for organizations to conduct thorough risk assessments and regularly review security protocols to ensure they are adequately prepared to handle advanced threats.
Attacks from APT groups, such as UAC-0063, pose a significant threat to organizations of all sizes and industries. As these attacks continue to evolve, it is important for businesses to remain vigilant and take proactive measures to defend against them.
Source: thehackernews.com
