HomeSecurityUkraine: XLL files distribute CABINETRAT malware

Ukraine: XLL files distribute CABINETRAT malware

Ukrainian security services have issued an urgent warning about a sophisticated malware campaign targeting government agencies and critical infrastructure via weaponized XLL files, distributed via compressed archives. The malicious campaign leverages Microsoft Excel add-in files containing the CABINETRAT backdoor.

CABINETRAT malware Ukraine XLL

The attack methodology involves distributing zip files containing seemingly legitimate XLL files with names such as “dodatok.xll” embedded in “500.zip” files. These files pretend to be documents related to border security incidents, taking advantage of current geopolitical tensions. The attackers aim to create a sense of urgency to increase the likelihood of the files being opened.

See also: FunkLocker Ransomware Leverages AI and Windows Tools

Upon execution, the malicious XLL files deploy a complex multi-layered payload that establishes permanent access to compromised systems . CERT-UA researchers noted the sophisticated approach of the campaign, identifying it as the work of the UAC-0245 threat group

The malware demonstrates advanced analysis evasion capabilities and represents a worrying shift towards more sophisticated Office- based attack methods targeting Ukraine's critical infrastructure . The technical sophistication of the campaign and targeting patterns suggest state support with significant resources dedicated to circumventing modern security defenses .

Ukraine: XLL files distribute CABINETRAT malware

CABINETRAT malware: How does it work?

The CABINETRAT malware uses a sophisticated multi-file deployment strategy that ensures persistent access to the system while evading detection mechanisms. When the initial XLL file is executed via Excel’s xlAutoOpen function, it creates three distinct components on the victim’s system: an executable file with a random 15-20 character name (internally called “runner.exe”) placed in both the Startup folder and %APPDATA%\Microsoft\Office\, an XLL loader file “BasicExcelMath.xll” placed in Excel’s XLSTART directory, and a PNG image file “Office.png” containing embedded shellcode.

See also: Chinese 'Phantom Taurus' targets organizations with Net-Star

The persistence  mechanism operates through multiple redundant pathways to ensure continuous access to the system . The malware creates registry entries in the Windows Run key with random names, creates scheduled tasks that run every 12 hours with limited permissions, and exploits Excel's auto-loading add-ins functionality.

Ukraine: XLL files distribute CABINETRAT malware

The runner executable launches Excel in hidden mode using the “/embed” parameter, automatically activating the malicious BasicExcelMath.xll add-in without displaying any visible Excel windows to users. The full infection chain from the initial execution of XLL to the final deployment of CABINETRAT includes extensive anti-analysis measures, including BIOS fingerprinting checks for virtualization software signatures, processor core and memory threshold validation, CPUID timing analysis for sandbox environment detection, and PEB debugging flag verification.

See also: RAM Battering Attack Bypasses Intel and AMD Security

These sophisticated evasion techniques demonstrate the advanced nature of the campaign and dedication to evading security research efforts.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS