Initial access broker repurposing techniques in targeted attacks against Ukraine

Threat Analysis Group

Initial access broker repurposing techniques in targeted attacks against Ukraine



text box of code

“Stolen Images Evidence” distribution service delivering UAC-0098 payload

example of "stolen images evidence"

“dropfiles[.]me” file sharing website delivering UAC-0098 payload

example of "“dropfiles[.]me” file sharing website delivering UAC-0098 payload

Phishing email used in a campaign exploiting CVE-2022-30190, translated from Ukrainian

text box of phishing email used in a campaign exploiting CVE-2022-30190, translated from Ukrainian