IDAT Loader Strikes Ukrainian Targets in Finland

Ukrainian entities situated in Finland have fallen victim to a malicious campaign that involves the distribution of a commercial remote access trojan known as Remcos RAT. This campaign utilizes a malware loader named IDAT Loader. The responsible threat actor, identified by the Computer Emergency Response Team of Ukraine (CERT-UA) as UAC-0184, has been linked to the attack.

Morphisec researcher Michael Dereviashkin, in a report shared with The Hacker News, highlighted that the attack, a component of the IDAT Loader, employs steganography as a technique. While steganographic techniques, commonly known as 'Stego,' are familiar, comprehending their role in defense evasion is crucial to developing effective defenses against such tactics.

IDAT Loader Shares DNA with Hijack Loader Malware

IDAT Loader, which shares similarities with another loader family called Hijack Loader, has been employed to deliver various payloads, including DanaBot, SystemBC, and RedLine Stealer in recent months. Additionally, the loader has been utilized by a threat actor known as TA544 to disseminate Remcos RAT and SystemBC through phishing attacks.

The phishing campaign, initially disclosed by CERT-UA in early January 2024, involves the use of war-themed lures to initiate an infection chain. This chain ultimately leads to the deployment of IDAT Loader, which then utilizes an embedded steganographic PNG to locate and extract Remcos RAT.

In a related development, CERT-UA revealed that defense forces in the country have been targeted through the Signal instant messaging app. The attackers distribute a booby-trapped Microsoft Excel document in this scenario, executing COOKBOX, a PowerShell-based malware capable of loading and executing cmdlets. This activity has been attributed to a cluster referred to as UAC-0149.

February 27, 2024
Loading...

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.