Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0184

Also known as: Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, WannaCryptor, Fox Kitten, UNC757, Parisite, BlackCat, CamoFei, Gamaredon APT, REvil, Mustang Panda

Description

UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks. They have been observed utilizing steganographic image files and the IDAT Loader to deliver the malware. The group has targeted the Armed Forces of Ukraine and impersonated military recruitment processes to infect systems with the Remcos RAT.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Energy
Telecommunications
Critical infrastructure
Non profit
Maritime
Media
Retail
Education
Utilities
Healthcare
Nuclear
Transportation
Manufacturing
Hospitality
Oil gas
Aerospace

Targeted Countries / Regions

UA
RU
CN
US
TW
AE
IR
NL
KP
IN
JP
SA
PK
AZ
BY
PL
KR
MX
ES
AU
IL

AI Analysis

No AI analysis yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  2. www.welivesecurity.com — Cited by web research for: WannaCryptor
  3. attack.mitre.org — Cited by web research for: Mustang Panda
  4. www.morphisec.com — Cited by web research for: T1001.002

Intel Summary

18

Techniques

40

Tools

0

Campaigns

12

IOCs

0

Observed Data

8

Tactics

Tags

Backdoor / C2
Government Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Ukraine (UA)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.