HomeSecurityUAC-0057 uses PDF invitation files to execute Shell Scripts

UAC-0057 uses PDF invitation files to execute Shell Scripts

A sophisticated cyberespionage campaign by the UAC-0057 is targeting Ukrainian and Polish organizations via PDF invitation files designed to execute malicious shell scripts.

UAC-0057 PDF invitation files Shell Scripts

The campaign, active since April 2025, demonstrates a targeted approach to infiltrating government and private networks through carefully designed social engineering. The threat actors behind this operation have leveraged seemingly legitimate invitation documents, including meeting invitations and official government communications, to gain initial access to target systems.

These malicious PDF files act as deceptive tools, while simultaneously deploying chains multi-stage infection that culminate in the execution of shell scripts and the deployment of sophisticated implants to access and collect data.

See also: INTERPOL arrested 1,209 cybercriminals in Africa

The campaign demonstrates remarkable sophistication in its execution methodology, using compressed files containing XLS spreadsheets with VBA macros. These macros are responsible for installing and loading Dynamic Link Libraries (DLLs), which collect system information and retrieve next-stage malware from command-and-control servers.

Campaign connection with the UAC-0057 group

HarfangLab researchers found striking similarities between this campaign and previous activities by the UAC-0057 group , also known as UNC1151 , FrostyNeighbor, or Ghostwriter. This cyberespionage group has documented ties to the Belarusian government and has targeted Eastern European countries, particularly Ukraine and Poland (primarily for intelligence gathering).

UAC-0057 uses PDF invitation files to execute Shell Scripts

The impact of malware extends beyond simple data theft, as threat actors have demonstrated the ability to maintain persistent access to compromised systemswhile evading detection through careful operational security practices. Infection chains reveal a methodical approach to system identification, with implants designed to collect detailed information about compromised environments before deploying additional payloads for extended exploitation.

See also: Colt: Warlock ransomware group sells customer data

The UAC-0057 infection mechanism represents a carefully orchestrated multi-stage attack that begins with the delivery of malicious files via spear-phishing campaigns. As previously mentioned, the messages include compressed files containing XLS spreadsheets with VBA macros, which act as the initial execution point for the malware deployment process. Once executed, these VBA macros exhibit various levels of obfuscation. The execution logic has evolved throughout the campaign. Early samples directly installed DLLs in temporary directories, while more recent variants use additional layers of sophistication, including Microsoft Cabinet (CAB) files and Link (LNK) files to hide the deployment process.

The infection chain proceeds through a systematic approach where the VBA macro writes encrypted DLL payloads to specific system directories such as %LOCALAPPDATA%\Serv\0x00bac729fe.log or %TEMP%\DefenderProtectionScope.log. These DLLs are then loaded using the built-in Windows regsvr32.exe utility with parameters designed to execute the malicious code while minimizing system notifications.

The first-stage implants, written in C# and decrypted via ConfuserEx, establish persistence through modifications to the Windows Registry and scheduled tasks. These implants collect extensive system data, including operating system details, hostname, CPU specifications, and installed antivirus products. They then proceed to transmit this data to a command-and-control infrastructure designed to blend in with legitimate web traffic.

See also: Programmer deployed kill switch code on employer's network

UAC-0057 uses PDF invitation files to execute Shell Scripts

This UAC-0057 is a prime example of highly sophisticated spear-phishing and shows that even organizations with mature infrastructures can fall victim if there is no constant vigilance. Below we suggest some ways to protect against such attacks:

1. Strengthen email security

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

  • Advanced Email Security Gateways with sandboxing for attachment analysis (PDF, XLS, CAB, LNK).
  • Enable DMARC, DKIM, SPF to check sender validity.
  • Custom filters to block suspicious compressed files in incoming emails.

2. Endpoint hardening

  • Disable macros by default and use only signed macros.
  • Monitoring the use of tools such as regsvr32.exe that are exploited for side-loading DLLs.
  • Installation of EDR (Endpoint Detection & Response) to detect persistence techniques (registry changes, scheduled tasks).

3. Network & Threat Hunting

  • Use threat intelligence feeds for C2 domains & IPs related to UAC-0057.
  • Network segmentation so that a breach of an endpoint does not lead to lateral movement.
  • Continuous analysis of network traffic anomalies (e.g. outbound traffic that mimics legitimate HTTPS but with suspicious patterns).

4. Education & awareness

  • Red team phishing simulations so that staff can recognize invitations and “official” documents that look plausible.
  • Training to report suspicious emails before opening attachments.

5. Incident Response readiness

  • Defined playbooks for spear-phishing attacks.
  • Frequent tabletop to simulate campaigns like that of UAC-0057.
  • Active collaboration with CERTs and ISACs for direct exchange of samples & IOCs.
📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS