CERT-UA disclosed a phishing campaign targeting Ukrainian organizations with a RAR archive themed around preserving video evidence of crimes by the Russian army. The lure delivered an executable that opened a decoy PDF styled as a National Police of Ukraine document, dropped supporting BAT, DAT, and DLL files into the Windows temporary directory, and established persistence through Run registry keys. CERT-UA tracked the activity as UAC-0026 and identified the DLL payload as HeaderTip, malware designed to download and execute additional DLLs while maintaining access on compromised systems.
Further analysis from eSentire assessed with high confidence that HeaderTip operates as both a backdoor and a loader, using obfuscation and Dynamic DNS through ChangeIP to sustain command-and-control connectivity. The malware reportedly communicated with a hardcoded C2 domain, including product2020.mrbasic[.]com, over HTTP POST requests on port 8080, with CERT-UA also linking infrastructure to 104[.]155.198.25. SentinelOne associated the campaign with the suspected Chinese threat actor Scarab, and CERT-UA said similar activity had been observed previously, indicating an established intrusion pattern rather than a one-off attack.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
CERT-UA publicly reported the campaign, describing the malicious RAR archive, dropped BAT/DAT/DLL files, Run key persistence, and C2 infrastructure including product2020.mrbasic[.]com and 104[.]155.198.25. The advisory also included host, network, and registry indicators of compromise.
CERT-UA detected the malware campaign on March 22, 2022 at a Ukrainian organization. It tracked the activity as UAC-0026 and classified the reconstructed DLL payload as HeaderTip.
The decoy PDF embedded in the malware carried National Police of Ukraine instructions on preserving video evidence of crimes by the Russian military. Its metadata indicated it was created, issued, and signed on March 16, 2022.
CERT-UA stated that similar attacks associated with this activity were observed in September 2020. This indicates the campaign or closely related tradecraft predates the 2022 disclosure.
The Scarab malware family was first observed in 2012 targeting organizations in Russia, Ukraine, the United States, Chile, and Syria. This establishes the earlier history of the threat actor later linked to the Ukraine-focused activity.
eSentire analyzed HeaderTip as a phishing-delivered malware that functions as both a backdoor and a loader, using Registry Run keys and ChangeIP-backed dynamic DNS for persistence and command-and-control. The analysis detailed the Ukrainian police-themed decoy PDF, dropped components, and HTTP POST communications over port 8080.
SentinelOne reported that the Ukraine-targeting activity was tied to the suspected Chinese threat actor Scarab. This added an attribution development to the HeaderTip/UAC-0026 story.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 15 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.