CERT-UA Warns of HTA-Delivered C# Malware Attacks Using Court Summons Lures
07.08.2025
956

Ukraine’s CERT-UA warns of UAC-0099 and Gamaredon phishing attacks using custom malware and social lures.
Ukraine’s CERT-UA has sounded the alarm on a fresh wave of cyberattacks, with threat actors UAC-0099 and Gamaredon deploying custom malware through phishing campaigns. These attacks cleverly disguise themselves as court summonses, leveraging social engineering to trick victims.
The malware, delivered via HTA files, is written in C# and is part of a sophisticated attack chain that includes PowerShell scripts and WinRAR exploits. This combo is designed to evade detection and establish a persistent presence on infected systems.

ESET researchers have linked these campaigns to ongoing cyber espionage activities targeting Ukrainian entities. The use of Visual Basic scripts and PowerShell highlights the attackers' preference for leveraging built-in Windows tools to minimize their footprint.
- • HTA files deliver C# malware disguised as court summonses.
- • PowerShell and WinRAR exploits used for persistence.
- • Linked to UAC-0099 and Gamaredon threat actors.
- • Targets include Ukrainian organizations.
This latest advisory underscores the evolving tactics of cybercriminals, blending technical sophistication with psychological manipulation. Stay vigilant and verify unexpected legal documents.
#malware#cyber threats#cyber espionage#social engineering#phishing
Got a topic? Write to ATLA WIRE on Telegram:t.me/atla_community

