Information Security 2 min read

CERT-UA issues warning about new UAC-0057 cyber threats

CERT-UA has detected new malware tools used by the UAC-0057 group. Explore the threats, NIS2 compliance risks, and key defense recommendations.

New toolkit of the UAC-0057 group

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of activity by the UAC-0057 hacking group, which is utilizing an updated malware toolkit. This arsenal is designed for multi-stage attacks on Ukrainian organizations, particularly critical infrastructure facilities.

  • OYSTERFRESH — provides initial access via phishing emails or compromised websites.
  • OYSTERSHUCK — used for privilege escalation within the system and lateral movement across the network.
  • OYSTERBLUES — establishes persistence in the system, communicates with command-and-control (C2) servers, and exfiltrates data.

What this means for the market

According to ENISA reports, phishing remains the primary initial access vector. For Ukrainian companies integrated into European supply chains, protecting against these threats is critical for NIS2 compliance. Non-compliance risks fines of up to €10 million or 2% of the company's global annual turnover.

A common mistake among organizations is deploying SIEM systems without established incident response (IR) processes or a qualified SOC team. On its own, a SIEM only detects anomalies but does not stop an attack, giving threat actors time to deploy malware.

Next steps

To defend against this threat, CERT-UA and cybersecurity experts recommend implementing a comprehensive approach:

  1. Implementing multi-factor authentication (MFA) and conducting regular employee training.
  2. Timely installation of security updates and robust patch management.
  3. Configuring correlation rules in SIEM to detect UAC-0057 indicators of compromise (IoCs).
  4. Segmenting the corporate network to restrict lateral movement by attackers.
  5. Developing and regularly testing incident response plans (IR playbooks).

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Further reading on the article topic.

  1. CERT-UA: UAC-0057 alert archive — cert.gov.ua
  2. CERT-UA: OYSTERFRESH malware article — cert.gov.ua