CSIDB logo
Incident

Computer Emergency Response Team of Ukraine

Incident posture

Attack window
Apr 2022
Location
Ukraine
Status
Historical
CIA posture
Available to members
Updated
2025-10-20 00:00

Linked entities

Victim
Computer Emergency Response Team of Ukraine
Threat actors
2 actors
Sources
1 source

Timeline

Occurred
Apr 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers targeted Ukrainian government agencies using IcedID malware delivered via malicious Excel documents and exploited a Zimbra vulnerability to deploy email forwarding rules for espionage. The Computer Emergency Response Team of Ukraine attributed the campaigns to threat clusters UAC-0041—previously linked to AgentTesla distribution—and UAC-0097, an unknown actor, with both operations aiming to infiltrate internal networks for cyber-espionage against critical infrastructure. The IcedID payload functioned as a banking trojan for credential theft and malware loading, while the Zimbra exploit facilitated unauthorized data exfiltration through compromised email systems.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

On April 14, 2022, the Computer Emergency Response Team of Ukraine (CERT-UA) identified two distinct cyber campaigns targeting Ukrainian government entities. The first attack involved phishing emails distributing malicious Excel documents titled "Mobilization Register.xls," which contained macros designed to download and execute IcedID malware, also known as BankBot. IcedID functioned as a modular banking trojan capable of harvesting credentials or deploying additional payloads for extended network compromise. CERT-UA attributed this campaign with moderate confidence to the threat cluster UAC-0041, an actor previously associated with distributing AgentTesla malware. The second campaign utilized emails carrying malicious JPG attachments that exploited CVE-2018-6882, a vulnerability in the Zimbra email collaboration platform, to establish unauthorized email forwarding rules. This technique aimed to intercept sensitive communications for espionage purposes. CERT-UA assigned this activity to a previously unidentified threat group designated UAC-0097.

Both operations sought unauthorized access to internal government networks to conduct cyber-espionage against critical Ukrainian agencies. The IcedID campaign leveraged social engineering tactics by using a document name suggesting military mobilization relevance, while the Zimbra exploit capitalized on unpatched vulnerabilities to manipulate email traffic silently. CERT-UA confirmed the objectives centered on persistent network infiltration for intelligence gathering rather than disruptive attacks. In response to the Zimbra exploitation, CERT-UA issued guidance advising organizations to apply security updates to mitigate CVE-2018-6882. The incidents exemplified ongoing malicious cyber operations against Ukrainian infrastructure during the 2022 conflict, with attribution assessments reflecting varying confidence levels based on tactical overlaps with historical threat actor patterns.

Sources

Sources available to members: 1 source.

CSIDB