This report provides an analysis of UAC-0063, an Advanced Persistent Threat (APT) group, focusing on indicators observed in campaigns, discovered malware samples, tools, and their targeted industries. The findings are based on data sourced from open intelligence and cybersecurity research. It is not an in-depth analysis of UAC-0063 tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
UAC-0063 is a cyber espionage group active since 2021, presumably linked to APT28. Initially operating in Central Asia (Kazakhstan, Kyrgyzstan, Mongolia, Tajikistan), it later expanded its attacks to Ukraine, Israel, India, and European countries (Germany, the United Kingdom, the Netherlands, Romania, and Georgia).
The phishing document uses a macros that disables macro protection in the registry, removes document protection, and deletes attacker-embedded shapes. It then creates a second document in C:\Users\[USER]\AppData\Local\Temp\, where malicious variables from settings.xml are copied before being silently executed in Word. This document contains a macro that extracts an HTA file with the HATVIBE code and saves it to C:\Users\[USER]\AppData\Local\Settings\locale. Finally, a scheduled task is created, which executes mshta.exe every four minutes to run the malicious code.
With the following TI lookup query, we can search through public tasks and identify this malicious activity.
TI lookup:
commandLine:"?C:\\Windows\\System32\\mshta.exe? C:\\Users\\admin\\Desktop\\locale"
SHA-256: e440bad60823642e8976528bd450364ce2542d15a69778ff20996eb107158b8d
Sample: ANY.RUN
SHA-256: 3eb696345c147d924a0407e37143c44e8be3563efa23eec914e6c9acee3f2beb
Sample: ANY.RUN
SHA256: 332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725
Sample: ANY.RUN
SHA-256: d2a0e6e5bdd66332fca965dad6126c1d6ef956e3782c431f1f41e99f45926331
Sample: ANY.RUN
f3474c17d8c33055c28cb45a04ab484f1492b0079b04eb850279114b4361f10c70e4305af8b00d04d95fba1f9ade222dd11fcd39a30a23176337847e54d7268cae5d4b9c1038f6840b563c868692f2aa89f15568bc19cc38caa8fd7efca977af2e91803687463201792ca7514fca07fabd7d98bc785beff4f4e5f7d8fc1ac2b4363f000702504ab19652dde2fde800e8b657d46d69e24b3607a81cacc486e3843cf8f57bd07fdd8e06b1630a3f27f3308f7dab01610b53398a296192ee600905MD5: da6d60f86a6c38127260e29fa91c1c8a
MD5: c3288a9d7fe494ae85a70af9f84e4d02
CVE-2024-23692
DownEx Espionage in Central Asia
1e46ef362b39663ce8d1e14c49899f0ebb7cf346c7db1c518b1a63c83e30c602a45106470f946ea6798f7d42878cff513ac42f25df0b600d6fc9eac73f01126114a8aad94b915831fc1d3a8e7e00a5df457eca2f6d11dd04ccce7308c1c327b7d310a9f28893857a0dc1f7c9b624d353d20e4fffbac3f46340b61ab8f7d578b15602da1f5b034c9d2d6105cdc471852b89f15568bc19cc38caa8fd7efca977afae5d4b9c1038f6840b563c868692f2aac273cdfcfd808efa49ec0ed4f1c976e0d11fcd39a30a23176337847e54d7268c70e4305af8b00d04d95fba1f9ade222d1492b0079b04eb850279114b4361f10cnet-certificate.services139.99.126.3884.32.188.123206.166.251.216UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY
enrollmentdm.comerrorreporting.netexperience-improvement.comgame-wins.cominternalsecurity.us lanmangraphics.comretaildemo.infoshared-rss.info telemetry-network.com tieringservice.comtrust-certificate.net 5.45.70.17845.136.198.18 45.136.198.184 45.136.198.189 46.183.219.228 84.32.188.23 185.62.56.47 185.158.248.198 185.167.63.42 194.31.55.131 212.224.86.69UAC-0063 Expands Cyber Espionage Operations
bd7d98bc785beff4f4e5f7d8fc1ac2b4 da6d60f86a6c38127260e29fa91c1c8a 2e91803687463201792ca7514fca07fa b657d46d69e24b3607a81cacc486e384 c1e4340ebe234478a410f757b18a128c 5d7a77efe12971bea8ae26206131fbb0 8f7dab01610b53398a296192ee600905 363f000702504ab19652dde2fde800e8 3cf8f57bd07fdd8e06b1630a3f27f330 10791a644da7d95ac4884872d8fa576d c3288a9d7fe494ae85a70af9f84e4d02 fdf7da11d37ba888fa7078d0f32fdd08 99d1de711a79eee936cde1ee58bd9adf lanmangraphics.comerrorreporting.net internalsecurity.us tieringservice.comautomation-embedding.com retaildemo.infoenrollmentdm.com underwearshopfor.com rss-feed-monitoring.com futuresfurnitures.com lookup.ink background-services.net cloud-mail.ink84.32.188.23185.62.56.47 212.224.86.69 46.183.219.228 195.80.150.54 185.167.63.42 185.158.248.198 91.237.124.142 38.180.87.154 91.202.5.49UAC-0063 Espionage in Central Asia and Kazakhstan
06e4084e2d043f216c0bc7931781ce3e1cea4eca1b6092c0e34b01a89e2a6dea3b87dc25a11b6268019d5eae49a6b93271dfdc262f2607cfefa35d196f72499747092548660d5200ea368aacbfe03435c88b6674b0975bb87a124736052bd7c36edf3d03bd38c800d5d1e297d59c2496968202358f4be47e1f07e57a52485e0cc61e9326421d05d62cafd6c04041ab1a8f57c0a21d424b9ca04b6a1fc275af19e3a0be8852d77771dc3f44f3e9a051e7fe56547b569aad5a178ae44ef31713b9e440bad60823642e8976528bd450364ce2542d15a69778ff20996eb107158b8defc99e6f3cdd10313c52a8ad099424e3f39ab85b75375b8db82717d61c7f0118fd78051817b5e2375c92d14588f9a4ba1adc92cc1564e55e6150ae350ed6c889background-services.netlookup.inkdownload-resourses.info2.58.15.158213.159.79.5638.180.207.13738.180.206.61UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY
rule APT_RU_TAG_110_HATVIBE
{
meta:
author = "Insikt Group, Recorded Future"
date = "2024-07-24"
description = "Detects HATVIBE .hta files"
version = "1.0"
hash = "332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725"
RF_MALWARE = "HATVIBE"
RF_MALWARE_ID = "rZ73vK"
strings:
$head1 = "<HEAD><HTA:APPLICATION ID=\""
$head2 = "\" APPLICATIONNAME=\""
$head3 = "\" WINDOWSTATE=\"normal\" MAXIMIZEBUTTON=\"no\" MINIMIZEBUTTON=\"no\"
CAPTION=\"no\" SHOWINTASKBAR=\"no\" BORDER=\"none\" SINGLEINSTANCE=\"yes\"></HEAD>"
$vbe1 = "#@~^"
$vbe2 = "^#~@</script></BODY></HTML>"
condition:
$head1 at 0 and $head2 and $head3 and $vbe1 and $vbe2
}
UAC-0063 Espionage in Central Asia and Kazakhstan
rule apt_UAC0063_HATVIBE_loader_obfuscated_VBA {
meta:
malware = "HATVIBE"
intrusion_set = "UAC-0063"
description = "Detects obfuscated HATVIBE HTA file"
source = "Sekoia.io"
creation_date = "2024-12-03"
classification = "TLP:GREEN"
hash = "332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725"
strings:
$ = "<HEAD><HTA:APPLICATION ID=\"" ascii
$ = "<span id=" ascii
$ = "<script Language=\"VBScript.Encode" ascii
condition:
filesize < 1MB
and all of them
}
UAC-0063 Espionage in Central Asia and Kazakhstan
rule apt_UAC0063_HATVIBE_loader_deobfuscated_VBA {
meta:
malware = "HATVIBE"
intrusion_set = "UAC-0063"
description = "Detects obfuscated HATVIBE HTA file"
source = "Sekoia.io"
creation_date = "2024-12-03"
classification = "TLP:GREEN"
hash = "0fa7e3ffb8a9ca246cc1f1e3f6118ced7a7b785de510d777b316dfcefdddb0be"
strings:
$ = "window.resizeTo 0,0" ascii
$ = ".InnerHTML =" ascii fullword
$ = "Chr(Asc(Mid(" ascii fullword
$ = "Xor Asc(Mid(" ascii fullword
$ = "Mod Len(" ascii fullword
$ = "\"script>"
condition:
3 of them
}
UAC-0063 Espionage in Central Asia and Kazakhstan
rule apt_UAC0063_HATVIBE_vbe {
meta:
malware = "HATVIBE"
intrusion_set = "UAC-0063"
description = "Detects the HATVIBE header in VBE"
source = "Sekoia.io"
creation_date = "2024-12-03"
classification = "TLP:GREEN"
hash = "78db9584ff4f7cd8f006eb6c12cac575"
strings:
// On Error Resume Next / window.resizeTo 0,0 / window.moveTo -2000,-2000
$header = "#@~^EwwAAA==6 P3MDKDP\"+k;:.PH+XY@#@&Skx9GhcD+kr\"+:W,!S!@#@&SkUNKARsW-n:WPR+Z!T~ +Z!T"
condition:
$header
}
UAC-0063 Espionage in Central Asia and Kazakhstan
rule apt_UAC0063_HATVIBE_decoded {
meta:
malware = "HATVIBE"
intrusion_set = "UAC-0063"
description = "Detects decoded HATVIBE's VBE"
source = "Sekoia.io"
creation_date = "2024-12-03"
classification = "TLP:GREEN"
strings:
$ = "window.resizeTo 0,0"
$ = "window.moveTo -2000,-2000"
$ = ".InnerHTML ="
$ = "& Chr(Asc(Mid("
condition:
all of them
}
UAC-0063 Espionage in Central Asia and Kazakhstan
rule apt_UAC0063_HATVIBE_vbe {
meta:
malware = "HATVIBE"
intrusion_set = "UAC-0063"
description = "Detects the HATVIBE header in VBE"
source = "Sekoia.io"
creation_date = "2024-12-03"
classification = "TLP:GREEN"
hash = "78db9584ff4f7cd8f006eb6c12cac575"
strings:
// On Error Resume Next / window.resizeTo 0,0 / window.moveTo -2000,-2000
$header = "#@~^EwwAAA==6 P3MDKDP\"+k;:.PH+XY@#@&Skx9GhcD+kr\"+:W,!S!@#@&SkUNKARsW-n:WPR+Z!T~ +Z!T"
condition:
$header
}
UAC-0063 Espionage in Central Asia and Kazakhstan
detection:
registry:
registry.value:
- AccessVBOM
- VbaWarnings
registry.data.strings: 'DWORD (0x00000001)'
cmdline_vbom:
process.command_line|contains|all:
- 'reg'
- 'add'
- '\SOFTWARE\Microsoft\Office\'
- 'AccessVBOM'
cmdline_warning:
process.command_line|contains|all:
- 'reg'
- 'add'
- '\SOFTWARE\Microsoft\Office\'
- 'VbaWarnings'
condition: registry or 1 of cmdline_*