In September 2025, the Computer Emergency Response Team of Ukraine (CERT-UA) identified a series of targeted cyber espionage attacks against members of the Ukrainian Officers Union. The attacks were attributed to a threat cluster designated as UAC-0245 and involved the deployment of a sophisticated backdoor known as CABINETRAT. The initial infection vector was the distribution of malicious Microsoft Excel XLL add-ins, which were delivered via ZIP archives shared over the Signal messaging app. These ZIP files were disguised as documents related to the detention of individuals attempting to cross the Ukrainian border, increasing the likelihood of successful social engineering. Once executed, the XLL add-in created multiple files on the victim's system, including an executable in the Startup folder, a persistent XLL file in the Excel XLSTART directory, and a PNG image. The attack chain included modifications to the Windows Registry to ensure persistence and leveraged Excel's hidden mode to execute the malicious add-in without user awareness. The XLL add-in extracted shellcode from the PNG file, which was identified as the CABINETRAT backdoor. CABINETRAT is a full-featured backdoor written in C, capable of gathering system information, enumerating installed programs, taking screenshots, listing directory contents, deleting files or directories, executing arbitrary commands, and facilitating file uploads and downloads. The malware communicates with its command-and-control server over a TCP connection, enabling remote operators to maintain long-term, stealthy access to compromised systems. To evade detection, both the XLL payload and the CABINETRAT shellcode incorporate anti-virtualization and anti-analysis techniques, such as checking for multiple processor cores, sufficient RAM, and the presence of common virtualization tools. CERT-UA's alert, referenced as CERT-UA#17479, highlights the ongoing nature of UAC-0245's operations and the increasing sophistication of cyber espionage campaigns targeting Ukraine. The attacks are part of a broader trend of state-sponsored cyber activity in the region, with a significant portion of incidents involving espionage and prepositioning for future operations. Security vendors, including SOC Prime, have responded by curating detection algorithms and Sigma rules to help organizations identify and mitigate UAC-0245 activity. These detection resources are aligned with the MITRE ATT&CK framework and are compatible with various SIEM, EDR, and data lake solutions, providing actionable intelligence for defenders. Security teams are encouraged to leverage these tools and monitor for indicators associated with CABINETRAT and UAC-0245 to proactively defend against similar threats. The incident underscores the importance of vigilance against novel attack vectors, such as XLL-based malware delivered through secure messaging platforms, and the need for continuous improvement in detection and response capabilities.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By early October 2025, CERT-UA publicly warned about the campaign and released technical details on CABINETRAT, including its persistence, anti-analysis behavior, and command-and-control methods. CERT-EU and SOC Prime also issued detection guidance and Sigma-based content to help defenders identify the activity.
After analyzing the activity, CERT-UA classified the operation under the distinct threat cluster UAC-0245 because the observed tactics, techniques, and procedures differed from previously documented XLL-based attacks. The campaign was noted as separate from earlier activity such as UAC-0002/Sandworm-linked use of XLL files.
In September 2025, CERT-UA identified a targeted cyber-espionage campaign against members of the Ukrainian Officers Union attributed to UAC-0245. The attackers used malicious Excel XLL add-ins delivered via Signal in a ZIP archive named "500.zip" to install the CABINETRAT backdoor.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcesocprime.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.