• About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Ransomware and Supply Chain Attacks Set Records in 2025

    Ransomware and Supply Chain Attacks Set Records in 2025

    Cloudflare

    Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path

    Google Gemini

    When Language Becomes the Attack Surface: Inside the Google Gemini Calendar Exploit

    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    Cyble Threat Landscape Report 2025

    The Year Ransomware Went Fully Decentralized: Cyble’s 2025 Threat Analysis

    Attack Surface Visibility Tops CISO Priorities for 2026

    Attack Surface Visibility Tops CISO Infrastructure Security Priorities for 2026

    CIRO cybersecurity incident

    Canada’s Investment Regulator Investigates Cyber Incident, Data Exposure Confirmed

    The Cyber Express Weekly Roundup

    The Cyber Express Weekly Roundup: Leadership Changes, Blackouts, Malware, and AI Safety Actions

    Germany

    Germany and Israel Deepen Cybersecurity Ties With New Security Pact

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Grok AI Image Abuse

    Grok Image Abuse Prompts X to Roll Out New Safety Limits

    RedVDS, RedVDS Tool, RedVDS Infrastructure, Microsoft, Fraud, Scam

    Microsoft Crushes Cybercrime Subscription Service Behind $40 Million Fraud Spree

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacker News
    • Ransomware News
    • Vulnerabilities
    Ransomware and Supply Chain Attacks Set Records in 2025

    Ransomware and Supply Chain Attacks Set Records in 2025

    Cloudflare

    Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path

    Google Gemini

    When Language Becomes the Attack Surface: Inside the Google Gemini Calendar Exploit

    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    Cyble Threat Landscape Report 2025

    The Year Ransomware Went Fully Decentralized: Cyble’s 2025 Threat Analysis

    Attack Surface Visibility Tops CISO Priorities for 2026

    Attack Surface Visibility Tops CISO Infrastructure Security Priorities for 2026

    CIRO cybersecurity incident

    Canada’s Investment Regulator Investigates Cyber Incident, Data Exposure Confirmed

    The Cyber Express Weekly Roundup

    The Cyber Express Weekly Roundup: Leadership Changes, Blackouts, Malware, and AI Safety Actions

    Germany

    Germany and Israel Deepen Cybersecurity Ties With New Security Pact

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    Grok AI Image Abuse

    Grok Image Abuse Prompts X to Roll Out New Safety Limits

    RedVDS, RedVDS Tool, RedVDS Infrastructure, Microsoft, Fraud, Scam

    Microsoft Crushes Cybercrime Subscription Service Behind $40 Million Fraud Spree

    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    U.S. Senators Push Apple and Google to Review Grok AI

    After EU Probe, U.S. Senators Push Apple and Google to Review Grok AI

    Government Cyber Action Plan

    UK Moves to Close Public Sector Cyber Gaps With Government Cyber Action Plan

    Donald_Trump

    Trump Orders US Exit from Global Cyber and Hybrid Threat Coalitions

    Cyber action plan, UK, cyber threats targeting political candidates

    UK Unveils £210M Cyber Overhaul as Nation Faces “Critically High” Digital Threat

    MongoBleed, MongoDB, CVE-2025-14847

    Critical ‘MongoBleed’ Flaw Exploited in the Wild to Leak Database Secrets

    DPDP Act Is Reshaping the Cyber Insurance Landscape

    Beyond Compliance: How India’s DPDP Act Is Reshaping the Cyber Insurance Landscape

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
    • All
    • How to
    • What is
    Google Chrome

    How to Remove Saved Passwords From Google Chrome (And Why You Should)

    DPDP Rules, Cyble, DPDP Act, Cyble Vantage

    How Cyble’s Front-Row Vantage Can Help You in Complying to India’s DPDP Act

    Cybersecurity Countries

    The Top 8 Countries Leading the Cyber Defense Race in 2025

    link building

    The Link Building Secrets Your Competitors Don’t Want You to Know

    Supply Chain Attack

    Supply Chain Resilience and Physical Security: Lessons for 2025

    Healthcare cybersecurity trends of 2024

    Healthcare Cybersecurity: 2024 Was Tough, 2025 May Be Better

    CEO's Guide to Take-Down Services

    Shield Your Organization: CEO’s Perspective on Take-Down Services

    Azure sign-in Microsoft

    Microsoft Announces Mandatory MFA for Azure Sign-ins to Bolster Cloud Defenses

    Signal Proxy, Signal, Signal Ban in Russia, Signal Ban in Venezuela, Bypass Signal Ban, How to Activate Signal Proxy, Signal Proxy Server

    How to Set Up Signal Proxy to Help Bypass Censorship in Russia and Venezuela

  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    Nicole Ozer appointment

    Nicole Ozer Joins CPPA to Drive Privacy and Digital Security Initiatives

    National Security Agency (NSA) appointment

    NSA Appoints Timothy Kosiba to Oversee Strategy and Cybersecurity Operations

    Shinhan Card data breach

    South Korea’s Shinhan Card Data Breach Affects 192,000 Merchants

    Cyble's Beenu-Recognized-by-ET-Edge-as-an-Impactful-CEO-2025_

    Beenu Arora, CEO & Co-Founder of Cyble, Recognized by ET Edge as an Impactful CEO 2025

    LastPass UK

    Password Manager LastPass Penalized £1.2m by ICO for Security Failures

    Coupang CEO Resigns

    Coupang CEO Resigns After Massive Data Breach Exposes Millions of Users

    Black Friday

    Black Friday Cybersecurity Survival Guide: Protect Yourself from Scams & Attacks

    Cyble and BOCRA Sign MoU

    Cyble and BOCRA Sign MoU to Strengthen Botswana’s National Cybersecurity Framework

    ARC Data Sale

    ARC Data Sale Scandal: Airlines’ Travel Records Used for Warrantless Surveillance

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Firewall Daily

Hackers Exploit RDP Tools to Breach Ukraine’s Notarial Offices, CERT-UA Reports

Ashish Khaitan by Ashish Khaitan
February 27, 2025
in Firewall Daily, Cyber News, Data Breach News, Hacker News
0
UAC-0173
757
SHARES
4.2k
VIEWS
Share on LinkedInShare on Twitter

CERT-UA, the Governmental Computer Emergency Response Team of Ukraine, reported a resurgence of the notorious criminal group UAC-0173. This group, known for orchestrating targeted cyberattacks on critical Ukrainian state infrastructure, has recently focused its efforts on Ukraine’s notary offices. Their primary goal: to gain unauthorized remote access to notary computers and manipulate state registers for monetary gain. 

The Ministry of Justice of Ukraine and the State Special Communications Service have been particularly active in defending against these attacks, which are part of a broader cyber-espionage campaign aimed at destabilizing Ukraine’s public records systems. The attacks employ sophisticated malware, advanced tools for system exploitation, and various techniques to circumvent security measures like User Account Control (UAC). 

The Attack Methodology of UAC-0173 Group  

The UAC-0173 group first emerged in late January 2025 when CERT-UA began monitoring suspicious activity targeting Ukrainian notary systems. The attackers used email messages disguised as official communications from the Ministry of Justice of Ukraine. These emails included links to malicious files such as “HAKA3.exe” and “Order of the Ministry of Justice of February 10, 2025 No. 43613.1-03.exe.” When opened, these files deployed the DARKCRYSTALRAT (DCRAT) malware, which allowed the attackers to establish initial access to the targeted systems. 

Once access was gained, the attackers installed additional malicious software, including RDPWRAPPER. This tool enables multiple Remote Desktop Protocol (RDP) sessions, effectively bypassing local security controls and allowing the attackers to gain direct access to the affected computers. By using tools like BORE, they were able to create RDP connections from the internet, making their operations more difficult to trace. 

The group also leveraged the FIDDLER proxy/sniffer tool to intercept login credentials used in web interfaces of state registers, while the XWORM stealer was employed to steal sensitive data such as usernames and passwords from the clipboard and keystrokes. 

CERT-UA’s Response and Cybersecurity Measures 

Upon discovering the renewed attacks, CERT-UA quickly took action to protect vulnerable systems. Working in collaboration with the Cybersecurity Commission of the Notarial Chamber of Ukraine, CERT-UA identified compromised systems across six regions of Ukraine. These systems were quickly isolated and secured, preventing the attackers from completing their malicious activities in some cases.

report-ad-banner

The Ministry of Justice of Ukraine, together with CERT-UA, also provided guidance to notaries to configure their systems in ways that would reduce the likelihood of successful attacks. Despite these efforts, the demand for services to alter state registers remains high, making it likely that UAC-0173 will continue to target notarial systems in the future. 

CERT-UA urged notaries to remain vigilant and report any suspicious activity immediately. The cooperation between Ukraine’s law enforcement agencies, the Cybersecurity Commission of the National Police of Ukraine, and CERT-UA remains vital in the ongoing fight against cybercriminals targeting the country’s public sector. 

Tools and Tactics 

UAC-0173 tools & tactics
Example of a chain of damage (Source: CERT-UA)

The attackers used an array of advanced tools to carry out their campaign. Key malware families involved include DCRAT and XWORM. These tools allowed the attackers to exfiltrate data, monitor victim activities, and further compromise systems. Additionally, the use of RDPWRAPPER enabled the attackers to execute parallel RDP sessions, increasing their control over the compromised systems.

Some of the malicious files identified by CERT-UA include: 

  • RDPWInst.exe – Used to install the RDPWrapper tool 
  • install.bat – A batch file to execute other malicious programs 
  • HAKA3.exe – The file responsible for installing the DCRAT malware 
  • bore.exe – Used to facilitate RDP connections from the internet 
  • xupwork3.exe – Likely another piece of malware used to maintain persistence on the compromised systems 

These tools were deployed through various methods, including email attachments and direct downloads from compromised websites. The attackers also used legitimate file storage services to host malicious files, making detection more difficult for traditional security tools. 

Indicators of Compromise (IOCs) 

The attack campaign also left a trail of indicators of compromise (IOCs), which help cybersecurity experts track the activities of UAC-0173. Some of the IOCs identified by CERT-UA include suspicious file names and URLs that were used in the attack: 

File Hashes: 

  • 3288c284561055044c489567fd630ac2 
  • cbad5b2ca73917006791882274f769e8 
  • A6b692e0ed3d5cd6fd20820dd06608ac 

Malicious URLs: 

  • hXXps://87.120.126[.]48/1pm 
  • hXXps://194[.]0.234.155/for your information.exe 
  • hXXps://91[.]92.246.18/upl/t1.exe 

By monitoring these indicators, cybersecurity teams can better identify ongoing attacks and implement countermeasures to protect Ukrainian state institutions from further breaches. 

The Role of RDPWRAPPER in the Attack 

One of the most malicious tools used by the attackers in this campaign was RDPWRAPPER. This tool is designed to bypass local security protocols and enable multiple RDP sessions on the infected machine. In combination with other tools like BORE and FIDDLER, RDPWRAPPER allowed the attackers to establish persistent access to notary systems, enabling them to execute further malicious actions such as altering state registers. 

The deployment of RDPWRAPPER also highlights the sophistication of the attack, as the tool effectively bypasses security measures such as User Account Control (UAC), which is designed to prevent unauthorized access to critical system functions. 

Conclusion 

As the demand for unauthorized modifications to Ukraine’s state registers remains high, UAC-0173 and other cybercriminal groups are expected to continue their efforts. The collaboration between CERT-UA, the Ministry of Justice of Ukraine, and law enforcement agencies will be critical in mitigating the impact of these attacks.

Additionally, the ongoing efforts to secure notarial systems and state registers, as well as the deployment of advanced cybersecurity tools, will be essential in reducing the attack surface and preventing further breaches. Notaries are urged to remain vigilant and report any suspicious activity to CERT-UA to enable timely response and mitigation.

Share this:

  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Reddit (Opens in new window) Reddit
  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • More
  • Email a link to a friend (Opens in new window) Email
  • Share on WhatsApp (Opens in new window) WhatsApp

Related

Tags: CERT-UAMinistry of Justice of UkraineState Special Communications ServiceThe Cyber ExpressThe Cyber Express NewsUAC-0173User Account Control
Previous Post

Kash Patel Steps In as FBI Chief, Commits to National Security and Integrity

Next Post

Remove These Extensions Now! Hackers Hijack Google Chrome Add-ons for Fraud

Next Post
Google Chrome

Remove These Extensions Now! Hackers Hijack Google Chrome Add-ons for Fraud

Threat Landscape Reports 2025

❮ ❯
Cyble-Vision


Follow Us On Google News

Latest Cyber News

Ransomware and Supply Chain Attacks Set Records in 2025
Cyber News

Ransomware and Supply Chain Attacks Set Records in 2025

January 20, 2026
Cloudflare
Firewall Daily

Cloudflare Zero-Day Let Attackers Bypass WAF via ACME Certificate Validation Path

January 20, 2026
Google Gemini
Firewall Daily

When Language Becomes the Attack Surface: Inside the Google Gemini Calendar Exploit

January 20, 2026
Google Chrome
Cyber News

How to Remove Saved Passwords From Google Chrome (And Why You Should)

January 19, 2026

Categories

Web Stories

Do This on Telegram, Your Bank Account Will Become Zero
Do This on Telegram, Your Bank Account Will Become Zero
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
If You Install the iOS 18 Beta, Your iPhone Could Be Hacked
Cricket World Cup Ticketing Systems Under Cybersecurity
Cricket World Cup Ticketing Systems Under Cybersecurity
Cyber Threats and Online Ticket Scams During the NBA Finals
Cyber Threats and Online Ticket Scams During the NBA Finals
Biometric Data Security: Protecting Sensitive Information
Biometric Data Security: Protecting Sensitive Information

About

The Cyber Express

#1 Trending Cybersecurity News and Magazine

The Cyber Express is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

 

Quick Links

  • About Us
  • Contact Us
  • Editorial Calendar
  • Careers
  • The Cyber Express by Cyble Vulnerability Disclosure Policy
  • Cyble Trust Portal

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
10080 North Wolfe Road, Suite SW3-200, Cupertino, CA, US 95014

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Knowledge Hub
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • Conference
    • Webinar
    • Endorsed Events
  • Advisory Board

© 2026 The Cyber Express - Cybersecurity News and Magazine.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?
-
00:00
00:00

Queue

Update Required Flash plugin
-
00:00
00:00
Do This on Telegram, Your Bank Account Will Become Zero If You Install the iOS 18 Beta, Your iPhone Could Be Hacked Cricket World Cup Ticketing Systems Under Cybersecurity Cyber Threats and Online Ticket Scams During the NBA Finals Biometric Data Security: Protecting Sensitive Information