UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware. They use obfuscation techniques like character encoding and base64 encoding to evade detection. The group leverages dynamic DNS services and Cloudflare Workers for their C2 infrastructure.
Executive Summary
UAC-0149 is a threat actor targeting the Armed Forces of Ukraine using COOKBOX malware. The group employs obfuscation techniques such as character encoding and base64 to evade detection, and their C2 infrastructure leverages dynamic DNS services and Cloudflare Workers. Their operations demonstrate moderate sophistication with a focus on evading detection through technical means.
Goals & Targeting
UAC-0149's primary objective appears to be targeting the Armed Forces of Ukraine, likely for espionage or disruption purposes. Their focus on military sectors suggests a state-sponsored or politically motivated group aiming to impair Ukraine's defensive capabilities. The use of COOKBOX malware indicates a preference for targeted and persistent attacks, with an emphasis on evading detection through advanced technical means.
Enhanced Description
UAC-0149 is an active threat actor primarily targeting the Armed Forces of Ukraine. The group deploys COOKBOX malware, which utilizes obfuscation techniques such as character encoding and base64 encoding to avoid detection by security tools. Their C2 infrastructure employs dynamic DNS services and Cloudflare Workers to maintain communication with compromised systems, enhancing their operational stealth. This actor demonstrates a clear intent to disrupt or gather information from Ukrainian military targets, possibly aligned with broader geopolitical interests.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0149 has been observed targeting Ukrainian military personnel since early reports emerged in 2023. Their campaigns exhibit persistence, with a focus on compromising systems and maintaining access through obfuscation. The group's reliance on legitimate services like Cloudflare Workers for C2 infrastructure suggests an ability to operate stealthily while targeting high-value assets.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the targeting patterns and TTPs, but limited visibility into the group's origins or long-term strategic goals. Additional information on their operational infrastructure and attack campaigns would improve understanding.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No IOCs linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
0
IOCs
0
Observed Data
0
Tactics