Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs post, oktober 1, 2025oktober 3, 2025 The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new targeted cyber attacks in the country using a backdoor called CABINETRAT. The activity, observed in September 2025, has been attributed to a threat cluster it tracks as UAC-0245. The agency said it spotted the attack following the discovery of software tools taking the form of XLL files, which refer to Microsoft Excel add-ins that are typically used to extend the functionality of Excel with custom functions. Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs: Ukraine Warns of CABINETRAT Backdoor + XLL Add-ins Spread via Signal ZIPs vulnerability 2025