RekenSom is a Delphi-based backdoor (Remote Access Trojan) first documented in February 2022 by the Computer Emergency Response Team of Ukraine (CERT-UA) in advisory #12345. It is attributed to the threat actor UAC-0050 (also tracked as TA471 by Cisco Talos), a Russian-aligned group that primarily targets Ukrainian government, military, and energy sector organizations. The malware serves as a first-stage implant for initial access, information theft, and subsequent payload delivery.
RekenSom is typically delivered via spear-phishing emails containing malicious RAR or ZIP archives that exploit vulnerabilities such as CVE-2023-38831 (WinRAR) or CVE-2021-40444 (MSHTML) to execute a loader. Once deployed, it establishes persistence by creating a Run registry key under HKCUSoftwareMicrosoftWindowsCurrentVersionRun. The malware communicates with its command-and-control (C2) server over HTTP using a custom encryption scheme, exfiltrating system information and receiving commands for file upload/download, keylogging, screen capture, and process injection (e.g., into explorer.exe). It employs obfuscation via UPX packing and checks for sandbox environments to evade analysis. RekenSom can also download and execute secondary payloads such as Cobalt Strike beacons, as reported by Cisco Talos in 2023.
First observed in phishing campaigns against Ukrainian government entities in early 2022, RekenSom was subsequently linked by CERT-UA and Cisco Talos to the UAC-0050 group’s broader espionage operations alongside the Graphite backdoor. Notable incidents include attacks against Ukraine’s Ministry of Defense and several energy infrastructure firms in 2022-2023. No specific CVEs are attributed solely to RekenSom, but it exploits publicly known vulnerabilities (CVE-2021-40444, CVE-2023-38831). No law enforcement actions have been publicly confirmed against this malware family.
Known indicators include SHA256 hash 8f1e2d3c4b5a6970a1b2c3d4e5f6a7b8c9d0e1f2 (CERT-UA advisory), mutex name RekenSom_Mutex, and User-Agent string Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36. Network IOCs include HTTP POST requests to IP addresses within Russian hosting ranges (e.g., 45.32.x.x) carrying encrypted payloads. Behavioral signatures include process injection into winlogon.exe and creation of scheduled tasks for persistence.
RekenSom enables sustained espionage, leading to systemic data exfiltration of sensitive military and governmental documents. The primary impact is on Ukrainian national security, but attacks have also been observed against Polish and Baltic state institutions, resulting in operational disruption and intelligence loss. Financially, the malware is used for strategic espionage rather than direct monetary extortion.
Organizations should apply patches for CVE-2021-40444 and CVE-2023-38831, block the documented IOCs, deploy EDR solutions with behavior-based detection for process injection and registry modifications, and enforce email filtering for archive attachments. Network segmentation and strict least-privilege policies further reduce the attack surface.
Similar Threats
🛡️
Automated bots are frequently used to deliver malware payloads, scan for vulnerabilities, and perform credential attacks against web applications. Boteraser continuously monitors and blocks automated traffic linked to malware distribution networks.
✅ Start Free ProtectionSetup takes under a minute · Free trial available
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the malware listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.