Also known as: Vermin, SickSync, TEMP.Vermin, VERMIN RELIC, APT34, Earth Preta, Stately Taurus, APT28, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257
Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin. They have targeted Ukrainian government infrastructure using malware like Spectr and legitimate tools like SyncThing for data exfiltration. Vermin has been active since at least 2018, using custom-made RATs like Vermin and open-source tools like Quasar for cyber-espionage. The group has resurfaced after periods of inactivity to conduct espionage operations against Ukraine's military and defense sectors.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC-0020, also known as Vermin or SickSync, is a threat actor linked to the Luhansk People’s Republic and believed to operate on behalf of the Kremlin. This group has been actively targeting Ukrainian government infrastructure since at least 2018, employing malware like Spectr and legitimate tools such as SyncThing for data exfiltration. Known for using custom-made RATs like Vermin and open-source frameworks like Quasar, UAC-0020 is engaged in cyber-espionage, resurfacing periodically to conduct operations against Ukraine's military and defense sectors.
Goals & Targeting
UAC-0020 appears to have a strategic focus on espionage and data exfiltration, targeting primarily Ukraine's military and defense sectors. Geopolitical motives suggest they operate in alignment with Russian interests, aiming to destabilize or gather intelligence on Ukrainian government functions. Their targeting of specific sectors underscores a long-term strategy aligned with broader adversarial goals against Украины.
Enhanced Description
UAC-0020, an enduring and sophisticated threat actor, has been identified as a Russia-linked group involved in adversarial activities targeting the Ukrainian government. Their modus operandi includes the use of custom malware (e.g., Spectr) and open-source tools (e.g., Quasar), demonstrating a capability to adapt and remain persistent despite periods of inactivity. This group's operations are indicative of cyber-espionage efforts aimed at gathering sensitive information, likely for the benefit of Russian interests. Their ability to blend legitimate tools with malicious activities makes detection challenging, posing significant risks to targeted organizations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0020 has conducted several campaigns targeting Ukrainian military and defense sectors since 2018. Known for resurfacing after periods of inactivity, their persistence indicates a long-term objective of espionage against critical infrastructure. Recent operations highlight their ability to adapt tactics, using both custom malware and legitimate tools for covert data extraction.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in UAC-0020's association with the Kremlin and Ukraine targeting, based on OSINT. Limited visibility into their infrastructure and specific TTPs beyond observed attacks.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics