Russia-associated cyber threat actors have been linked to an ongoing espionage campaign targeting Kazakhstan, aiming to support the Kremlin’s efforts to collect economic and political intelligence across Central Asia.
A new wave of targeted cyberattacks on Kazakhstan has caught the attention of cybersecurity experts. These attacks have been attributed to a hacking group identified as UAC-0063, which is believed to be linked to the Russian intelligence agency GRU. This group shares close ties with the infamous APT28 group (also known as Fancy Bear, Sednit, and Sofacy), internationally notorious for cyber operations aimed at extracting political and economic intelligence from foreign states.
Early in 2023, the Ukrainian Computer Emergency Response Team (CERT-UA) reported on the activities of UAC-0063. The group utilizes various malware families such as HATVIBE, CHERRYSPY, and STILLARCH, exclusively observed in its operations. These malicious tools have been strategically deployed against government institutions in Ukraine as well as entities across Central Asia and Europe.
According to the threat analysis by Recorded Future’s Insikt Team, UAC-0063 conducts a focused espionage campaign targeting diplomatic relations, NGOs, the energy sector, and academic institutions. Central Asia, Eastern Europe, and Ukraine are particularly prominent in the scope of these operations.
Spear-Phishing Attacks with Sophisticated Infection Chains
A particularly noteworthy aspect of these attacks is the use of spear-phishing documents modeled on legitimate materials from Kazakhstan’s Ministry of Foreign Affairs. These documents serve as bait to initiate a multi-stage infection chain. Known as “Double-Tap,” this chain ultimately leads to the installation of the HATVIBE malware. Experts suspect that the malicious documents were either stolen in prior cyber operations or acquired through other covert means.
The infection chain begins with a manipulated macro file that, when opened by the victim, creates a second, hidden Word file in the temporary user directory (“C:\Users[USER]\AppData\Local\Temp”). This file contains an embedded HTML Application (HTA) process that injects a VBS-based backdoor named HATVIBE.
HATVIBE functions as a loader, receiving VBS modules from a remote server, which eventually paves the way for deploying a Python-based backdoor called CHERRYSPY. The interplay of these components allows attackers to extract sensitive information effectively.
The analysis by Sekoia highlights the advanced techniques employed by the attackers. For instance, the malicious code is concealed in a “settings.xml” file, making it difficult for conventional security solutions to detect. Additionally, a scheduled task is created without invoking the typical “schtasks.exe” process, complicating detection further. Another sophisticated tactic involves checking the execution time of the initial macro file. If the code detects alterations in execution time—an indication of emulation by security systems—it automatically terminates execution.

Connections to APT28 and Strategic Espionage Goals
HATVIBE’s activities show significant overlaps with previous campaigns by the APT28 group, particularly the Zebrocy operations. These similarities allow researchers to attribute UAC-0063 to the Russian hacking group with medium confidence.
The primary focus of these cyber operations appears to be collecting strategic intelligence on diplomatic relations between Kazakhstan and other Central Asian states. This includes not only economic and political data but also information on defense strategies and scientific collaborations. The selection of Kazakhstan as a target is especially noteworthy, given the country’s central role in the region and its significance for both Russia and other geopolitical players.
Russian Surveillance Technology SORM and Its Geopolitical Implications
Parallel to the HATVIBE attacks, research by Recorded Future indicates that several countries in Central Asia and Latin America have acquired Russian surveillance technology. The SORM platform (System for Operative Investigative Activities) is offered by Russian providers such as Citadel, Norsi-Trans, and Protei, enabling extensive interception and storage of electronic communications.
SORM is a surveillance apparatus that allows full control over landline and mobile communications, internet traffic, social media, and even Wi-Fi. These data can be stored in a searchable database, enabling authorities to conduct targeted monitoring. While officially intended for crime prevention, such systems are often misused to suppress political opposition, journalists, and activists.
It is believed that countries such as Belarus, Kazakhstan, Kyrgyzstan, and Uzbekistan, as well as Cuba and Nicaragua, have acquired this technology. The proliferation of SORM demonstrates how Russia extends its geopolitical influence through technological exports to strategically significant regions. Particularly in former Soviet states, which Russia continues to view as within its sphere of influence, this technology bolsters Moscow’s position.
Conclusion: Security Risks from Targeted Cyberattacks
The HATVIBE attacks and the increasing adoption of SORM technologies shed light on Russia’s geopolitical ambitions. They reveal a deliberate intent to extract economic and political intelligence while destabilizing regional stability through covert influence.
To learn more about the threat landscape posed by cyberattacks, visit Schumm Defense’s website at SchummDefense.com.

