Executive Summary
In September 2025, CERT-UA reported a targeted cyberattack campaign against Ukrainian organizations involving the CABINETRAT backdoor. The threat group tracked as UAC-0245 employed malicious Microsoft Excel XLL add-ins, disguised within ZIP archives distributed via Signal messenger, to covertly establish persistent backdoor access on victim systems. These XLL files, once executed, enabled attackers to conduct reconnaissance, data theft, and potential lateral movement inside compromised networks, raising concerns about operational disruption, espionage, and data confidentiality.
This incident highlights the evolving threat landscape where adversaries leverage secure messaging platforms and file add-ins to bypass traditional email security and endpoint controls. The appearance of CABINETRAT underscores increasing sophistication in malware delivery and emphasizes the need for modern controls and East-West traffic visibility.
Why This Matters Now
Attackers are adapting to evade detection by using trusted collaboration tools like Signal and advanced file formats such as XLLs, making traditional security layers less effective. Organizations must act swiftly to address gaps in east-west traffic visibility, file-based defense, and zero trust segmentation, as similar threat campaigns are rapidly proliferating across sectors.
Attack Path Analysis
The attack began with the delivery of a malicious XLL file disguised as a ZIP attachment via Signal, compromising the initial target. Once opened, the CABINETRAT backdoor was installed, enabling the attacker to escalate privileges on the victim host. Using this access, the threat actor explored lateral movement opportunities within the cloud or networked environment. CABINETRAT established persistent command and control to receive attacker instructions and exfiltrate data. Sensitive information was likely extracted through encrypted or covert outbound channels. Finally, the backdoor’s presence enabled further disruptive actions, and potential long-term compromise within the environment.
Kill Chain Progression
Initial Compromise
Description
User received a malicious XLL file via Signal ZIP, leading to CABINETRAT installation upon execution.
Related CVEs
CVE-2021-40444
CVSS 8.8A remote code execution vulnerability exists in Microsoft MSHTML that allows attackers to craft malicious ActiveX controls to be used by Microsoft Office documents, leading to arbitrary code execution.
Affected Products:
Microsoft Windows – Windows 10, Windows 11, Windows Server 2019, Windows Server 2022
Exploit Status:
exploited in the wildCVE-2017-0199
CVSS 7.8A remote code execution vulnerability exists when Microsoft Office and WordPad fail to properly handle specially crafted files, allowing an attacker to run arbitrary code in the context of the current user.
Affected Products:
Microsoft Office – Office 2010, Office 2013, Office 2016
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
User Execution: Malicious File
Spearphishing Attachment
Obfuscated Files or Information
Command and Scripting Interpreter: Visual Basic
Application Layer Protocol: Web Protocols
Ingress Tool Transfer
Boot or Logon Autostart Execution: Registry Run Keys / Startup Folder
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Incident Response Testing and Training
Control ID: 12.10.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Protect Against Malicious Attachments
Control ID: Protect: Email/Phishing Protections
NIS2 Directive – Incident Handling & Preventive Measures
Control ID: Article 21(2)(d)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
Ukraine CERT-UA warning indicates state-sponsored CABINETRAT backdoor targeting government systems through XLL files, requiring enhanced east-west traffic security and zero trust segmentation.
Financial Services
CABINETRAT backdoor via Excel XLL files poses significant risk to financial institutions, necessitating robust egress security and threat detection capabilities for regulatory compliance.
Information Technology/IT
IT sector faces high exposure to CABINETRAT backdoor attacks through XLL add-ins, requiring comprehensive multicloud visibility and inline IPS protection against targeted campaigns.
Defense/Space
Defense contractors vulnerable to UAC-0245 threat cluster using CABINETRAT backdoor, demanding encrypted traffic protection and anomaly detection for critical infrastructure security.
Sources
- Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPshttps://thehackernews.com/2025/10/ukraine-warns-of-cabinetrat-backdoor.htmlVerified
- CERT-UA warns of a new malicious campaign deploying CABINETRAT backdoorhttps://www.cybersecurity-help.cz/blog/4984.htmlVerified
- Detecção de ataques UAC-0245: backdoor CABINETRAT usado em ataques direcionados contra a Ucrâniahttps://socprime.com/pt/blog/latest-threats/detect-uac-0245-attacks/Verified
- Ukraine Warns of CABINETRAT Malware Via XLL Fileshttps://www.secnews.gr/en/665588/ukraine-warns-cabinetrat-xll-files/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Applying CNSF Zero Trust controls such as east-west traffic security, zero trust segmentation, egress policy enforcement, and inline threat detection would have contained CABINETRAT, limiting movement and blocking malicious C2 and exfiltration actions. Distributed, workload-centric policies and visibility would significantly reduce the attacker’s ability to escalate, pivot, and maintain hidden access.
Control: Threat Detection & Anomaly Response
Mitigation: Would trigger alerts upon anomalous process or unusual endpoint activity.
Control: Zero Trust Segmentation
Mitigation: Limits attack impact to the initially compromised asset by enforcing least-privilege segmentation.
Control: East-West Traffic Security
Mitigation: Blocks unapproved internal network flows associated with attacker movement.
Control: Inline IPS (Suricata) and Egress Security & Policy Enforcement
Mitigation: Detects, blocks, or flags outbound C2 traffic using known bad signatures and domain filtering.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents unauthorized outbound transfers to unapproved domains or IPs.
Provides continuous visibility, inspection, and automated response to further malicious behaviors.
Impact at a Glance
Affected Business Functions
- Government Communications
- Border Security Operations
- Critical Infrastructure Management
Estimated downtime: 5 days
Estimated loss: $500,000
Potential exposure of sensitive government documents and personal data of individuals involved in border security incidents.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral attacker movement and minimize blast radius.
- • Enforce egress security controls to block unauthorized command & control and data exfiltration traffic.
- • Deploy inline IDS/IPS (such as Suricata) for real-time detection and blocking of known malicious network activity.
- • Enhance east-west workload monitoring and anomaly detection to catch suspicious movement or privilege escalation attempts.
- • Maintain continuous cloud-native visibility and enforce microsegmentation through distributed policy automation.



