BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Ukraine Hit by CABINETRAT Backdoor Cyberattacks via Excel XLL Files

CERT-UA Uncovers CABINETRAT Backdoor Cyber Attacks Targeting Ukraine via Malicious Excel Add-Ins Distributed on Signal in September 2025

  • The Computer Emergency Response Team of Ukraine (CERT-UA) has identified new targeted cyber attacks using a backdoor named CABINETRAT.
  • The attacks were observed in September 2025 and linked to the threat group UAC-0245.
  • Malicious Microsoft Excel add-in files (XLL files) are distributed via Signal, disguised as a border detention document.
  • CABINETRAT backdoor collects system information, executes commands, and communicates over TCP.
  • The backdoor and payload use anti-analysis techniques to evade detection on virtual machines.

In September 2025, the Computer Emergency Response Team of Ukraine (CERT-UA) detected cyber attacks targeting Ukrainian systems. The attacks employed a backdoor called CABINETRAT, delivered through malicious Microsoft Excel add-in files (XLL files). These files were spread using ZIP archives shared on the Signal messaging app, disguised as documents about the detention of individuals trying to cross the Ukrainian border.

- Advertisement -

CERT-UA attributed the activity to the threat cluster tracked as UAC-0245. The malicious XLL files create several executable files on infected computers, including an EXE in the Startup folder, a copy of the XLL file named “BasicExcelMath.xll” in the Excel startup directory, and a PNG image titled “Office.png.” The Malware modifies Windows Registry settings to maintain persistence and runs Excel in a hidden mode to execute the XLL add-in.

The XLL add-in extracts shellcode stored inside the PNG image. This shellcode, classified as CABINETRAT, is designed as a backdoor written in C. It gathers system information such as installed programs, captures screenshots, lists directory contents, deletes files or directories, executes commands, and transfers files. CABINETRAT communicates with a remote server using a TCP connection.

Both the XLL payload and CABINETRAT incorporate anti-analysis features to avoid detection. They check for virtual environments by detecting virtualization software like VMware and VirtualBox, and require at least two processor cores and 3 GB of RAM before executing.

This announcement follows a recent warning from Fortinet FortiGuard Labs about phishing attacks in Ukraine. Those attacks impersonated the National Police of Ukraine and delivered malware such as Amatera Stealer and PureMiner to steal data and mine cryptocurrency.

- Advertisement -

For more details on the CERT-UA report, visit their official page here. Information on XLL files can be found at Microsoft’s documentation here.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Oklo’s Loss Widens as Revenue Remains Absent

Oklo's Q1 net loss deepened to $33.1 million, meeting analyst expectations according to Fiscal.ai.The...

Bermuda to Move Financial Services to Stellar Network

The government of Bermuda will transition key financial services to the Stellar blockchain network...

Senate confirms Kevin Warsh to Federal Reserve board

The US Senate has confirmed Kevin Warsh as a Federal Reserve Governor, setting the...

Fake OpenAI Model on Hugging Face Spreads Malware

A fake Hugging Face repo impersonating OpenAI's Privacy Filter model reached #1 trending, using...

OpenAI Daybreak AI Hunts Software Bugs Like Anthropic’s Mythos

OpenAI launched "Daybreak," a Cybersecurity AI initiative designed to automatically detect and patch software...

Must Read

Symbiosis Crypto Bridge: Your Guide to Moving Assets Between Blockchains

What is a Cross-Chain Crypto Bridge?Why Choose Symbiosis for Your Cross-Chain Needs?Support for 50+ BlockchainsAutomatic Routing for the Best RatesNo Need for RegistrationDirect Wallet...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading