HomeSecurityPhishing attack targets Ukraine's largest bank

Phishing attack targets Ukraine's largest bank

A new phishing campaign was orchestrated by hackers UAC-0006 and targets customers of PrivatBank, Ukraine's largest bank.

phishing Ukrainian bank PrivatBank

Cybersecurity analysts at CloudSEK have identified the attack that uses archives password-protected. These contain malicious JavaScript, VBScript, or LNK files to evade detection.

See also: Mobile phishing: What is it and how to protect yourself?

Since November 2024, hackers UAC-0006 have been observed carrying out payment-related phishing attacks. The phishing messages contain:

  • JavaScript and VBScript files that execute PowerShell commands
  • The SmokeLoader malware for command and control (C2) communication.

The above facilitates unauthorized access, execution of malicious payloads, and continuous monitoring of compromised systems.

The latest attack begins with a phishing email containing a password-protected ZIP or RAR file . Once opened, the extracted JavaScript or VBScript file launches a series of processes that inject malicious code into legitimate Windows binaries.

See also: Microsoft Teams: Phishing alerts coming to everyone in February

Phishing attacks pose many risks to individuals and businesses. They can allow access to important data and accounts after stealing credentials and financial information.

hacker UAC-0006

Protection

Users should be wary of messages they receive from strangers or from supposedly well-known companies. Many times, phishing attacks start with a simple message asking for the user's login details.

Next, they should regularly update their software, including the operating system and applications. These updates often include security that can protect the user from the latest threats.

See also: New phishing campaign targets mobile devices with malicious PDFs

Using reliable security software, such as an antivirus or security app, can help protect against attacks. These tools can identify and block suspicious websites or messages that are trying to steal user information.

Finally, users should be careful when downloading applications from the internet. Many times, applications that seem innocent may contain hidden code that can steal user information or cause other security threats.

Source: www.infosecurity-magazine.com

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS