База обновлений ESET NOD32 TAS-IX
Uralmountainssamples Rar (SAFE — 2025)
Creates scheduled tasks or registry keys under names like WindowsUpdater to stay on the system. 💡 Key Takeaway
"UralMountainsSamples.rar" is a malicious archive associated with , a Russian-aligned threat actor group known for cyber-espionage targeting Ukrainian government agencies. 🛡️ Threat Profile Target: Ukrainian state bodies and defense entities.
While specific hashes change, these characteristics are common in this campaign: UralMountainsSamples rar
📍 It is a verified tool for data theft and remote surveillance used in active conflict zones.
The .rar file usually contains a lure document (PDF or Word) and a hidden LNK file or executable. ⚙️ Infection Chain Creates scheduled tasks or registry keys under names
Often uses hardcoded IP addresses or Dynamic DNS services (like duckdns.org ).
The attack follows a multi-stage execution pattern to evade detection: The attack follows a multi-stage execution pattern to
The shortcut triggers a PowerShell script or a side-loading vulnerability.