TLDR:
- CERT-UA Warns of new phishing attacks linked to Vermin
- Phishing messages contain alleged PoW photos and lead to malware installation
The Computer Emergency Response Team of Ukraine (CERT-UA) has issued a warning about new phishing attacks associated with a threat cluster known as UAC-0020 or Vermin. These attacks involve sending phishing messages with photos of alleged prisoners of war (PoW) from the Kursk region, prompting recipients to click on a link that leads to a ZIP archive containing malware. The malware installs components of known spyware SPECTR as well as a new malware called FIRMACHAGENT, which retrieves stolen data and sends it to a remote server.
Vermin, the group behind these attacks, has been linked to security agencies of the Luhansk People’s Republic (LPR) and has previously targeted defense forces in Ukraine with similar campaigns. SPECTR, the malware involved, is designed to harvest a wide range of information including files, screenshots, credentials, and data from messaging apps like Element, Signal, Skype, and Telegram.
Organizations are advised to stay vigilant against these phishing attacks and ensure their systems are protected from such malware installations.