CERT-UA reported that UAC-0063 compromised a Ukrainian research institution by abusing a hijacked employee email account to resend a legitimate-looking message carrying a malicious macro-enabled document. The infection chain launched an HTA-based HATVIBE backdoor, established persistence with a scheduled task, and enabled attackers to deploy a newer CHERRYSPY variant compiled as a .pyd DLL. CERT-UA said the intrusion was aided by weak defenses, including missing MFA on email, local administrator privileges, and the lack of controls blocking Office macros, mshta.exe, and Python execution; it also noted that CVE-2024-23692 in HFS HTTP File Server had likely been used in separate HATVIBE infections.
Bitdefender said the same cluster, also tracked as TAG-110, has run a broader cyber-espionage operation since 2022 against government bodies and diplomatic missions across Central Asia and Europe, including embassies in Germany, the UK, the Netherlands, Romania, Georgia, Kazakhstan, and Afghanistan. The group reportedly reused weaponized Word documents stolen from earlier victims to infect new ones and deployed follow-on tools including DownExPyer/CherrySpy, PyPlunderPlug, and keylogging components tied to LOGPIE for file theft, screenshot capture, command execution, removable-media collection, and credential-related surveillance. CERT-UA assessed with medium confidence that UAC-0063 is linked to APT28/UAC-0001 and Russia's GRU, while Bitdefender said the targeting and tradecraft align with Russian espionage interests but do not yet conclusively prove that connection.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
CERT-UA reported that an analogous malicious DOCX lure was uploaded from Armenia and targeted the Armenian Ministry of Defense while purporting to come from Kyrgyzstan's defense ministry. The document reused a similar macro-based infection approach associated with UAC-0063.
On July 8, 2024, UAC-0063 compromised a Ukrainian scientific research institution by resending a legitimate-looking email from a hijacked employee account with a malicious macro-enabled attachment. The infection chain deployed the HATVIBE backdoor, established persistence with a scheduled task, and later delivered a CHERRYSPY variant compiled as a .pyd DLL.
CERT-UA reported numerous cases in June 2024 where HATVIBE was installed through likely exploitation of CVE-2024-23692 in Rejetto HFS HTTP File Server. The agency said this showed UAC-0063 used multiple initial compromise vectors.
Bitdefender Labs said it has monitored UAC-0063, also tracked as TAG-110, since 2022 as part of an ongoing cyber-espionage campaign targeting high-value organizations.
Bitdefender published research describing UAC-0063 as an active cyber-espionage campaign targeting government entities and diplomatic missions in Central Asia and several European countries. The company said the group's interests and tradecraft overlap with Russian espionage objectives but that available technical evidence was insufficient to confirm or refute a link to APT28.
Bitdefender said the latest infection attempt cited in its report occurred on November 21, 2024, using a link to a lure document named "Инфо о запуске нового проекта ec.doc" hosted on cloud-mail[.]ink. The attempt followed the group's established macro-enabled HATVIBE delivery pattern.
CERT-UA disclosed its investigation of the July 8 intrusion, identified HATVIBE and CHERRYSPY malware, and assessed with medium confidence that UAC-0063 is associated with APT28/UAC-0001 linked to Russia's GRU General Staff. The report also published infrastructure and file indicators tied to the activity.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.