Double-Tap Campaign by UAC-0063

The threat actor is conducting a spearphishing campaign to deliver malicious attachments, maintain persistence, and establish command and control.

Engage Report: Double-Tap Campaign – Espionage in Central Asia

  1. A malicious macro in the initial Word document creates a second blank document and weaponizes it with another malicious macro.
  2. The second macro creates a scheduled task named “SettingsService Dispatch” using RegisterTaskDefinition.
  3. This task executes an HTA file containing the HATVIBE backdoor every four minutes using mshta.exe.