Close Menu
    Latest Post

    Philips Hue Essential Lights: Great Value, But Original Bulbs Offer Superior Dimming

    January 13, 2026

    Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military

    January 13, 2026

    US Nears Trade Deal with Taiwan, Including TSMC Fab Commitment in Arizona

    January 13, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Philips Hue Essential Lights: Great Value, But Original Bulbs Offer Superior Dimming
    • Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military
    • US Nears Trade Deal with Taiwan, Including TSMC Fab Commitment in Arizona
    • Enhanced Search Suggestions in Firefox
    • Biologists Treat LLMs Like Aliens to Uncover Their Secrets
    • Behind the Scenes: Developing the Question Assistant
    • Was Windows 8 Really That Bad? A Revisit 13 Years Later
    • Lenovo’s New Rollable Concept Could Be the Ideal Gaming Laptop
    Facebook X (Twitter) Instagram Pinterest Vimeo
    NodeTodayNodeToday
    • Home
    • AI
    • Dev
    • Guides
    • Products
    • Security
    • Startups
    • Tech
    • Tools
    NodeTodayNodeToday
    Home»Security»Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military
    Security

    Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military

    Samuel AlejandroBy Samuel AlejandroJanuary 13, 2026No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    src 13ue0py featured
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Image 1

    A cyber threat group aligned with Russia, identified as UAC-0184, has been observed targeting Ukrainian military and government organizations. The group utilizes the Viber messaging platform to deliver malicious ZIP archives in these attacks.

    According to a technical report from the 360 Threat Intelligence Center, this group consistently engaged in extensive intelligence gathering operations against Ukrainian military and government sectors throughout 2025.

    The hacking group, also known as Hive0156, has a history of using war-themed deceptive tactics in phishing emails. These campaigns aim to deliver Hijack Loader to Ukrainian targets, which then facilitates Remcos RAT infections.

    CERT-UA first documented this threat actor in January 2024. Later attack campaigns showed the group utilizing messaging applications such as Signal and Telegram to deliver malware. Recent discoveries by the Chinese security vendor indicate a continued evolution in these delivery methods.

    The current attack methodology begins with Viber, used as the initial entry point to distribute malicious ZIP archives. These archives contain several Windows shortcut (LNK) files, which are disguised as legitimate Microsoft Word and Excel documents to deceive recipients into opening them.

    These LNK files are engineered to display a decoy document to the victim, reducing suspicion, while simultaneously executing Hijack Loader in the background. This is achieved by retrieving a second ZIP archive, named “smoothieks.zip,” from a remote server via a PowerShell script.

    Image 2

    Hijack Loader is reconstructed and deployed in memory through a multi-stage process. This process incorporates techniques like DLL side-loading and module stomping to bypass detection by security software. The loader also scans the system for installed security products, including those from Kaspersky, Avast, BitDefender, AVG, Emsisoft, Webroot, and Microsoft, by computing the CRC32 hash of their respective programs.

    In addition to establishing persistence through scheduled tasks, the loader attempts to circumvent static signature detection. It then covertly executes Remcos RAT by injecting it into “chime.exe.” This remote administration tool provides attackers with capabilities to manage the compromised endpoint, deploy further payloads, monitor user activities, and exfiltrate data.

    The 360 Threat Intelligence Center noted that while Remcos RAT is marketed as legitimate system management software, its potent intrusive features lead to its frequent use by malicious actors for cyber espionage and data theft. The tool’s graphical user interface (GUI) control panel allows attackers to conduct both automated batch management and precise manual operations on a victim’s host.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleUS Nears Trade Deal with Taiwan, Including TSMC Fab Commitment in Arizona
    Next Article Philips Hue Essential Lights: Great Value, But Original Bulbs Offer Superior Dimming
    Samuel Alejandro

    Related Posts

    Security

    Dems pressure Google, Apple to drop X app as international regulators turn up heat

    January 12, 2026
    Security

    Grok Is Generating Sexual Content Far More Graphic Than What’s on X

    January 11, 2026
    Security

    Most Parked Domains Now Serving Malicious Content

    January 10, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Latest Post

    ChatGPT Mobile App Surpasses $3 Billion in Consumer Spending

    December 21, 202512 Views

    Automate Your iPhone’s Always-On Display for Better Battery Life and Privacy

    December 21, 202510 Views

    Creator Tayla Cannon Lands $1.1M Investment for Rebuildr PT Software

    December 21, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    About

    Welcome to NodeToday, your trusted source for the latest updates in Technology, Artificial Intelligence, and Innovation. We are dedicated to delivering accurate, timely, and insightful content that helps readers stay ahead in a fast-evolving digital world.

    At NodeToday, we cover everything from AI breakthroughs and emerging technologies to product launches, software tools, developer news, and practical guides. Our goal is to simplify complex topics and present them in a clear, engaging, and easy-to-understand way for tech enthusiasts, professionals, and beginners alike.

    Latest Post

    Philips Hue Essential Lights: Great Value, But Original Bulbs Offer Superior Dimming

    January 13, 20260 Views

    Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military

    January 13, 20260 Views

    US Nears Trade Deal with Taiwan, Including TSMC Fab Commitment in Arizona

    January 13, 20260 Views
    Recent Posts
    • Philips Hue Essential Lights: Great Value, But Original Bulbs Offer Superior Dimming
    • Russia-Aligned Hackers Exploit Viber to Target Ukrainian Government and Military
    • US Nears Trade Deal with Taiwan, Including TSMC Fab Commitment in Arizona
    • Enhanced Search Suggestions in Firefox
    • Biologists Treat LLMs Like Aliens to Uncover Their Secrets
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms & Conditions
    • Disclaimer
    • Cookie Policy
    © 2026 NodeToday.

    Type above and press Enter to search. Press Esc to cancel.