Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0020

Also known as: Vermin, SickSync, TEMP.Vermin, VERMIN RELIC, APT34, Earth Preta, Stately Taurus, APT28, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0063, TAG-110, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM, APT-C-41, Inception Framework, UNC1151, DEV-0257

Description

Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin. They have targeted Ukrainian government infrastructure using malware like Spectr and legitimate tools like SyncThing for data exfiltration. Vermin has been active since at least 2018, using custom-made RATs like Vermin and open-source tools like Quasar for cyber-espionage. The group has resurfaced after periods of inactivity to conduct espionage operations against Ukraine's military and defense sectors.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Education
Non profit
Healthcare
Energy
Manufacturing
Media
Critical infrastructure
Think tank
Aerospace
Pharmaceutical
Aviation
Hospitality
Maritime
Transportation
Legal services
Chemical
Retail
Information technology
Nuclear
Entertainment
Mining
Gaming
Utilities
Oil gas
Construction

Targeted Countries / Regions

RU
CN
US
UA
IL
AE
PK
IR
VN
BY
IN
JP
KR
TW
PL
SA
TR
LB
DE
KZ
GB
AU
IT
FR
SG
KP
IQ
MX
ES
CA
NL
RO
NG
AZ

AI Analysis

· 1 week ago

Executive Summary

UAC-0020, also known as Vermin or SickSync, is a threat actor linked to the Luhansk People’s Republic and believed to operate on behalf of the Kremlin. This group has been actively targeting Ukrainian government infrastructure since at least 2018, employing malware like Spectr and legitimate tools such as SyncThing for data exfiltration. Known for using custom-made RATs like Vermin and open-source frameworks like Quasar, UAC-0020 is engaged in cyber-espionage, resurfacing periodically to conduct operations against Ukraine's military and defense sectors.

Goals & Targeting

UAC-0020 appears to have a strategic focus on espionage and data exfiltration, targeting primarily Ukraine's military and defense sectors. Geopolitical motives suggest they operate in alignment with Russian interests, aiming to destabilize or gather intelligence on Ukrainian government functions. Their targeting of specific sectors underscores a long-term strategy aligned with broader adversarial goals against Украины.

Enhanced Description

UAC-0020, an enduring and sophisticated threat actor, has been identified as a Russia-linked group involved in adversarial activities targeting the Ukrainian government. Their modus operandi includes the use of custom malware (e.g., Spectr) and open-source tools (e.g., Quasar), demonstrating a capability to adapt and remain persistent despite periods of inactivity. This group's operations are indicative of cyber-espionage efforts aimed at gathering sensitive information, likely for the benefit of Russian interests. Their ability to blend legitimate tools with malicious activities makes detection challenging, posing significant risks to targeted organizations.

Key Capabilities

  • Custom RATs (Vermin)
  • Open-source frameworks (Quasar)
  • Malware (Spectr)
  • Legitimate tools for exfiltration

MITRE ATT&CK Tactics

Operations Security
Espionage

ATT&CK Techniques

T1485
T1059

Software / Tooling

Spectr
Vermin RAT
Quasar Framework
SyncThing

Campaigns & Victims

UAC-0020 has conducted several campaigns targeting Ukrainian military and defense sectors since 2018. Known for resurfacing after periods of inactivity, their persistence indicates a long-term objective of espionage against critical infrastructure. Recent operations highlight their ability to adapt tactics, using both custom malware and legitimate tools for covert data extraction.

IOC Patterns

  • C2 traffic over specific protocols
  • File hashes from Spectr malware
  • Spear-phishing emails

Recommended Actions

  • Harden access controls with MFA
  • Monitor network traffic for anomalies
  • Patch systems regularly
  • Use EDR solutions

Suggested Tags

APT
Espionage
Cyber-espionage
Ukraine

Confidence Assessment

High confidence in UAC-0020's association with the Kremlin and Ukraine targeting, based on OSINT. Limited visibility into their infrastructure and specific TTPs beyond observed attacks.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 9 Domain 8 SHA-1 Hash 1 IPv4 Address 2

References

  1. www.eset.com — Cited by web research for: APT34
  2. attack.mitre.org — Cited by web research for: T1087
  3. attack.mitre.org — Cited by web research for: IcedID
  4. www.cybereason.com — Cited by web research for: Rubeus
  5. www.cybereason.com — Cited by web research for: NSIS

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Data Exfiltration
Government Targeting
Espionage
Cyber-espionage
Ukraine

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.