Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0149

Description

UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware. They use obfuscation techniques like character encoding and base64 encoding to evade detection. The group leverages dynamic DNS services and Cloudflare Workers for their C2 infrastructure.

AI Analysis

· 1 week ago

Executive Summary

UAC-0149 is a threat actor targeting the Armed Forces of Ukraine using COOKBOX malware. The group employs obfuscation techniques such as character encoding and base64 to evade detection, and their C2 infrastructure leverages dynamic DNS services and Cloudflare Workers. Their operations demonstrate moderate sophistication with a focus on evading detection through technical means.

Goals & Targeting

UAC-0149's primary objective appears to be targeting the Armed Forces of Ukraine, likely for espionage or disruption purposes. Their focus on military sectors suggests a state-sponsored or politically motivated group aiming to impair Ukraine's defensive capabilities. The use of COOKBOX malware indicates a preference for targeted and persistent attacks, with an emphasis on evading detection through advanced technical means.

Enhanced Description

UAC-0149 is an active threat actor primarily targeting the Armed Forces of Ukraine. The group deploys COOKBOX malware, which utilizes obfuscation techniques such as character encoding and base64 encoding to avoid detection by security tools. Their C2 infrastructure employs dynamic DNS services and Cloudflare Workers to maintain communication with compromised systems, enhancing their operational stealth. This actor demonstrates a clear intent to disrupt or gather information from Ukrainian military targets, possibly aligned with broader geopolitical interests.

Key Capabilities

  • Obfuscation techniques (character encoding, base64)
  • Deployment of COOKBOX malware
  • Use of dynamic DNS for C2 infrastructure
  • Leveraging Cloudflare Workers for command and control
  • Spear-phishing campaigns targeting military personnel

MITRE ATT&CK Tactics

Initial Access
Execution
Defense Evasion
Collection
Exfiltration

ATT&CK Techniques

T1059
T1059.003
T1566
T1566.002
T1070

Software / Tooling

COOKBOX malware (likely a custom framework)

Campaigns & Victims

UAC-0149 has been observed targeting Ukrainian military personnel since early reports emerged in 2023. Their campaigns exhibit persistence, with a focus on compromising systems and maintaining access through obfuscation. The group's reliance on legitimate services like Cloudflare Workers for C2 infrastructure suggests an ability to operate stealthily while targeting high-value assets.

IOC Patterns

  • Spear-phishing emails with malicious links or documents targeting military personnel
  • Dynamic DNS domain registrations associated with the actor's C2 infrastructure
  • Network traffic originating from Cloudflare Worker services
  • Registry changes or persistence mechanisms linked to COOKBOX malware

Recommended Actions

  • Implement advanced phishing detection solutions to identify spear-phishing attempts
  • Monitor network traffic for suspicious domains or IP addresses associated with dynamic DNS services
  • Enhance endpoint protection to detect and block obfuscated malicious payloads
  • Conduct regular audits of system configurations to remove potential backdoors

Suggested Tags

APT
espionage
Ukraine-focused
military-sector-targeting

Confidence Assessment

High confidence in the targeting patterns and TTPs, but limited visibility into the group's origins or long-term strategic goals. Additional information on their operational infrastructure and attack campaigns would improve understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

Backdoor / C2
APT
espionage
Ukraine-focused
military-sector-targeting

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.