The government sector of Ukraine was targeted with spear-phishing emails with a malicious attachment which appeared to be sent from the State Emergency Service of Ukraine.
Opening the attachment resulted in VBScript code creating a scheduled task for persistence and a PowerShell script downloading the DolphinCape information stealer.
The malicious software is capable of exfiltrating system information as well as screenshots of the infected device.