UAC-0063 Attacks

Overview

This report provides an analysis of UAC-0063, an Advanced Persistent Threat (APT) group, focusing on indicators observed in campaigns, discovered malware samples, tools, and their targeted industries. The findings are based on data sourced from open intelligence and cybersecurity research. It is not an in-depth analysis of UAC-0063 tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

About UAC-0063

UAC-0063 is a cyber espionage group active since 2021, presumably linked to APT28. Initially operating in Central Asia (Kazakhstan, Kyrgyzstan, Mongolia, Tajikistan), it later expanded its attacks to Ukraine, Israel, India, and European countries (Germany, the United Kingdom, the Netherlands, Romania, and Georgia).

Origin Country

  • Russia

Motivation

  • Espionage

First Seen

  • 2021

Targeted Countries

  • Armenia
  • China
  • Greece
  • Hungary
  • India
  • Kazakhstan
  • Kyrgyzstan
  • Tajikistan
  • Turkmenistan
  • Ukraine
  • Uzbekistan
  • Germany
  • Netherlands
  • Romania
  • Georgia
  • Afghanistan
  • United Kingdom
  • Israel

Industry Attacked

  • Government
  • Energy
  • Education

HATVIBE

  • UAC-0063 Expands Cyber Espionage Operations

The phishing document uses a macros that disables macro protection in the registry, removes document protection, and deletes attacker-embedded shapes. It then creates a second document in C:\Users\[USER]\AppData\Local\Temp\, where malicious variables from settings.xml are copied before being silently executed in Word. This document contains a macro that extracts an HTA file with the HATVIBE code and saves it to C:\Users\[USER]\AppData\Local\Settings\locale. Finally, a scheduled task is created, which executes mshta.exe every four minutes to run the malicious code.

With the following TI lookup query, we can search through public tasks and identify this malicious activity.

TI lookup: commandLine:"?C:\\Windows\\System32\\mshta.exe? C:\\Users\\admin\\Desktop\\locale"

Phishing document deploying HATVIBE via macros

  • SHA-256: e440bad60823642e8976528bd450364ce2542d15a69778ff20996eb107158b8d

  • Sample: ANY.RUN

HATVIBE (main .hta file)

  • SHA-256: 3eb696345c147d924a0407e37143c44e8be3563efa23eec914e6c9acee3f2beb

  • Sample: ANY.RUN

  • SHA256: 332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725

  • Sample: ANY.RUN

DownEx

  • DownEx Espionage in Central Asia

  • SHA-256: d2a0e6e5bdd66332fca965dad6126c1d6ef956e3782c431f1f41e99f45926331

  • Sample: ANY.RUN

IOCs (Click to expand)
  • MD5: f3474c17d8c33055c28cb45a04ab484f
  • MD5: 1492b0079b04eb850279114b4361f10c
  • MD5: 70e4305af8b00d04d95fba1f9ade222d
  • MD5: d11fcd39a30a23176337847e54d7268c
  • MD5: ae5d4b9c1038f6840b563c868692f2aa
  • MD5: 89f15568bc19cc38caa8fd7efca977af

CHERRYSPY

  • UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY

  • UAC-0063 Expands Cyber Espionage Operations

IOCs (Click to expand)
  • MD5: 2e91803687463201792ca7514fca07fa
  • MD5: bd7d98bc785beff4f4e5f7d8fc1ac2b4
  • MD5: 363f000702504ab19652dde2fde800e8
  • MD5: b657d46d69e24b3607a81cacc486e384
  • MD5: 3cf8f57bd07fdd8e06b1630a3f27f330
  • MD5: 8f7dab01610b53398a296192ee600905

PyPlunderPlug

  • UAC-0063 Expands Cyber Espionage Operations

  • MD5: da6d60f86a6c38127260e29fa91c1c8a

LOGPIE

  • UAC-0063 Expands Cyber Espionage Operations

  • MD5: c3288a9d7fe494ae85a70af9f84e4d02

CVEs Used

  • UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY

  • CVE-2024-23692

IOC Summary

DownEx Espionage in Central Asia

IOCs (Click to expand)
  • MD5: 1e46ef362b39663ce8d1e14c49899f0e
  • MD5: bb7cf346c7db1c518b1a63c83e30c602
  • MD5: a45106470f946ea6798f7d42878cff51
  • MD5: 3ac42f25df0b600d6fc9eac73f011261
  • MD5: 14a8aad94b915831fc1d3a8e7e00a5df
  • MD5: 457eca2f6d11dd04ccce7308c1c327b7
  • MD5: d310a9f28893857a0dc1f7c9b624d353
  • MD5: d20e4fffbac3f46340b61ab8f7d578b1
  • MD5: 5602da1f5b034c9d2d6105cdc471852b
  • MD5: 89f15568bc19cc38caa8fd7efca977af
  • MD5: ae5d4b9c1038f6840b563c868692f2aa
  • MD5: c273cdfcfd808efa49ec0ed4f1c976e0
  • MD5: d11fcd39a30a23176337847e54d7268c
  • MD5: 70e4305af8b00d04d95fba1f9ade222d
  • MD5: 1492b0079b04eb850279114b4361f10c
  • domain: net-certificate.services
  • ip: 139.99.126.38
  • ip: 84.32.188.123
  • ip: 206.166.251.216

UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY

IOCs (Click to expand)
  • domain: enrollmentdm.com
  • domain: errorreporting.net
  • domain: experience-improvement.com
  • domain: game-wins.com
  • domain: internalsecurity.us
  • domain: lanmangraphics.com
  • domain: retaildemo.info
  • domain: shared-rss.info
  • domain: telemetry-network.com
  • domain: tieringservice.com
  • domain: trust-certificate.net
  • ip: 5.45.70.178
  • ip: 45.136.198.18
  • ip: 45.136.198.184
  • ip: 45.136.198.189
  • ip: 46.183.219.228
  • ip: 84.32.188.23
  • ip: 185.62.56.47
  • ip: 185.158.248.198
  • ip: 185.167.63.42
  • ip: 194.31.55.131
  • ip: 212.224.86.69

UAC-0063 Expands Cyber Espionage Operations

IOCs (Click to expand)
  • MD5: bd7d98bc785beff4f4e5f7d8fc1ac2b4
  • MD5: da6d60f86a6c38127260e29fa91c1c8a
  • MD5: 2e91803687463201792ca7514fca07fa
  • MD5: b657d46d69e24b3607a81cacc486e384
  • MD5: c1e4340ebe234478a410f757b18a128c
  • MD5: 5d7a77efe12971bea8ae26206131fbb0
  • MD5: 8f7dab01610b53398a296192ee600905
  • MD5: 363f000702504ab19652dde2fde800e8
  • MD5: 3cf8f57bd07fdd8e06b1630a3f27f330
  • MD5: 10791a644da7d95ac4884872d8fa576d
  • MD5: c3288a9d7fe494ae85a70af9f84e4d02
  • MD5: fdf7da11d37ba888fa7078d0f32fdd08
  • MD5: 99d1de711a79eee936cde1ee58bd9adf
  • domain: lanmangraphics.com
  • domain: errorreporting.net
  • domain: internalsecurity.us
  • domain: tieringservice.com
  • domain: automation-embedding.com
  • domain: retaildemo.info
  • domain: enrollmentdm.com
  • domain: underwearshopfor.com
  • domain: rss-feed-monitoring.com
  • domain: futuresfurnitures.com
  • domain: lookup.ink
  • domain: background-services.net
  • domain: cloud-mail.ink
  • ip: 84.32.188.23
  • ip: 185.62.56.47
  • ip: 212.224.86.69
  • ip: 46.183.219.228
  • ip: 195.80.150.54
  • ip: 185.167.63.42
  • ip: 185.158.248.198
  • ip: 91.237.124.142
  • ip: 38.180.87.154
  • ip: 91.202.5.49

UAC-0063 Espionage in Central Asia and Kazakhstan

IOCs (Click to expand)
  • SHA-256: 06e4084e2d043f216c0bc7931781ce3e1cea4eca1b6092c0e34b01a89e2a6dea
  • SHA-256: 3b87dc25a11b6268019d5eae49a6b93271dfdc262f2607cfefa35d196f724997
  • SHA-256: 47092548660d5200ea368aacbfe03435c88b6674b0975bb87a124736052bd7c3
  • SHA-256: 6edf3d03bd38c800d5d1e297d59c2496968202358f4be47e1f07e57a52485e0c
  • SHA-256: c61e9326421d05d62cafd6c04041ab1a8f57c0a21d424b9ca04b6a1fc275af19
  • SHA-256: e3a0be8852d77771dc3f44f3e9a051e7fe56547b569aad5a178ae44ef31713b9
  • SHA-256: e440bad60823642e8976528bd450364ce2542d15a69778ff20996eb107158b8d
  • SHA-256: efc99e6f3cdd10313c52a8ad099424e3f39ab85b75375b8db82717d61c7f0118
  • SHA-256: fd78051817b5e2375c92d14588f9a4ba1adc92cc1564e55e6150ae350ed6c889
  • domain: background-services.net
  • domain: lookup.ink
  • domain: download-resourses.info
  • ip: 2.58.15.158
  • ip: 213.159.79.56
  • ip: 38.180.207.137
  • ip: 38.180.206.61

YARA

UAC-0063 Targets Asia and Europe with HATVIBE and CHERRYSPY


rule APT_RU_TAG_110_HATVIBE
{
      meta:
          author = "Insikt Group, Recorded Future"
          date = "2024-07-24"
          description = "Detects HATVIBE .hta files"
          version = "1.0"
          hash = "332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725"
          RF_MALWARE = "HATVIBE"
          RF_MALWARE_ID = "rZ73vK"
      strings:
          $head1 = "<HEAD><HTA:APPLICATION ID=\""
          $head2 = "\" APPLICATIONNAME=\""
          $head3 = "\" WINDOWSTATE=\"normal\" MAXIMIZEBUTTON=\"no\" MINIMIZEBUTTON=\"no\"
          CAPTION=\"no\" SHOWINTASKBAR=\"no\" BORDER=\"none\" SINGLEINSTANCE=\"yes\"></HEAD>"
          $vbe1 = "#@~^"
          $vbe2 = "^#~@</script></BODY></HTML>"
      condition:
          $head1 at 0 and $head2 and $head3 and $vbe1 and $vbe2
}

UAC-0063 Espionage in Central Asia and Kazakhstan


rule apt_UAC0063_HATVIBE_loader_obfuscated_VBA {
    meta:
        malware = "HATVIBE"
        intrusion_set = "UAC-0063"
        description = "Detects obfuscated HATVIBE HTA file"
        source = "Sekoia.io"
        creation_date = "2024-12-03"
        classification = "TLP:GREEN"
        hash = "332d9db35daa83c5ad226b9bf50e992713bc6a69c9ecd52a1223b81e992bc725"
    strings:
        $ = "<HEAD><HTA:APPLICATION ID=\"" ascii
        $ = "<span id=" ascii
        $ = "<script Language=\"VBScript.Encode" ascii
    condition:
        filesize < 1MB
        and all of them
}

UAC-0063 Espionage in Central Asia and Kazakhstan


rule apt_UAC0063_HATVIBE_loader_deobfuscated_VBA {
    meta:
        malware = "HATVIBE"
        intrusion_set = "UAC-0063"
        description = "Detects obfuscated HATVIBE HTA file"
        source = "Sekoia.io"
        creation_date = "2024-12-03"
        classification = "TLP:GREEN"
        hash = "0fa7e3ffb8a9ca246cc1f1e3f6118ced7a7b785de510d777b316dfcefdddb0be"
    strings:
        $ = "window.resizeTo 0,0" ascii
        $ = ".InnerHTML =" ascii fullword
        $ = "Chr(Asc(Mid(" ascii fullword
        $ = "Xor Asc(Mid(" ascii fullword
        $ = "Mod Len(" ascii fullword
        $ = "\"script>"
    condition:
        3 of them
}

UAC-0063 Espionage in Central Asia and Kazakhstan


rule apt_UAC0063_HATVIBE_vbe {
    meta:
        malware = "HATVIBE"
        intrusion_set = "UAC-0063"
        description = "Detects the HATVIBE header in VBE"
        source = "Sekoia.io"
        creation_date = "2024-12-03"
        classification = "TLP:GREEN"
        hash = "78db9584ff4f7cd8f006eb6c12cac575"
    strings:
        // On Error Resume Next / window.resizeTo 0,0 / window.moveTo -2000,-2000
        $header = "#@~^EwwAAA==6    P3MDKDP\"+k;:.PH+XY@#@&Skx9GhcD+kr\"+:W,!S!@#@&SkUNKARsW-n:WPR+Z!T~ +Z!T"
    condition:
        $header
}

UAC-0063 Espionage in Central Asia and Kazakhstan


rule apt_UAC0063_HATVIBE_decoded {
    meta:
        malware = "HATVIBE"
        intrusion_set = "UAC-0063"
        description = "Detects decoded HATVIBE's VBE"
        source = "Sekoia.io"
        creation_date = "2024-12-03"
        classification = "TLP:GREEN"
    strings:
        $ = "window.resizeTo 0,0"
        $ = "window.moveTo -2000,-2000"
        $ = ".InnerHTML ="
        $ = "& Chr(Asc(Mid("
    condition:
        all of them
}

UAC-0063 Espionage in Central Asia and Kazakhstan


rule apt_UAC0063_HATVIBE_vbe {
    meta:
        malware = "HATVIBE"
        intrusion_set = "UAC-0063"
        description = "Detects the HATVIBE header in VBE"
        source = "Sekoia.io"
        creation_date = "2024-12-03"
        classification = "TLP:GREEN"
        hash = "78db9584ff4f7cd8f006eb6c12cac575"
    strings:
        // On Error Resume Next / window.resizeTo 0,0 / window.moveTo -2000,-2000
        $header = "#@~^EwwAAA==6    P3MDKDP\"+k;:.PH+XY@#@&Skx9GhcD+kr\"+:W,!S!@#@&SkUNKARsW-n:WPR+Z!T~ +Z!T"
    condition:
        $header
}

Sigma

UAC-0063 Espionage in Central Asia and Kazakhstan


detection:
  registry:
    registry.value:
      - AccessVBOM
      - VbaWarnings
    registry.data.strings: 'DWORD (0x00000001)'
  cmdline_vbom:
    process.command_line|contains|all:
      - 'reg'
      - 'add'
      - '\SOFTWARE\Microsoft\Office\'
      - 'AccessVBOM'
  cmdline_warning:
    process.command_line|contains|all:
      - 'reg'
      - 'add'
      - '\SOFTWARE\Microsoft\Office\'
      - 'VbaWarnings'
  condition: registry or 1 of cmdline_*

References

  • https://go.recordedfuture.com/hubfs/reports/CTA-RU-2024-1121.pdf
  • https://blog.sekoia.io/double-tap-campaign-russia-nexus-apt-possibly-related-to-apt28-conducts-cyber-espionage-on-central-asia-and-kazakhstan-diplomatic-relations/
  • https://www.bitdefender.com/en-us/blog/businessinsights/uac-0063-cyber-espionage-operation-expanding-from-central-asia
  • https://www.bitdefender.com/en-us/blog/businessinsights/deep-dive-into-downex-espionage-operation-in-central-asia