Also known as: APT28, TAG-110, including government entities, diplomatic missions, CHERRYSPY, CherrySpy, APT34, Earth Preta, Stately Taurus, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM
UAC‑0063 operates as an advanced persistent threat, executing complex supply‑chain and in‑org infiltration campaigns that are hallmarks of APT28’s operational tempo. At the initial access phase, adversaries use spear‑phishing emails adorned with macro‑enabled .dotm documents to deploy backdoor loaders such as HATVIBE (HTA wrapper) and CHERRYSPY (a Python‑based implant). Once resident, the malware exfiltrates information through multiple vectors: encrypted HTTP PUT/GET traffic, USB‑based extraction via PyPlunderPlug, and optional cloud uploads. Privilege escalation is routinely achieved with the CVE‑2022‑38028 Windows kernel vulnerability and other abuse‑elevation mechanisms, allowing lateral movement across office networks. The actor’s toolset exhibits a mix of proprietary code and open‑source components. HATVIBE integrates obfuscated VBScript that manipulates registry keys (AccessVBOM) and schedules persistently via Task Scheduler. CHERRYSPY incorporates keylogging, clipboard monitoring through LOGPIE, screen capture with the Python "mss" library, and credential dumping from local stores and browsers. Both implants communicate using AES‑encrypted JSON messages, often prefixed with hex markers to bypass inspection. In addition, UAC‑0063 deploys ancillary tools such as Authentic Antics ransomware during opportunistic attacks. Defensive evasion is a core focus: the malware employs steganography to hide its code inside innocuous images or documents, uses XOR‑encoded URLs, and renews TLS certificates on compromised domains. The attackers also exploit public‑facing services (e.g., HFS HTTP File Server) for initial compromise of remote targets. Overall, UAC‑0063 demonstrates a sophisticated, multi‑stage attack lifecycle that blends advanced malware development with opportunistic exploitation of known vulnerabilities.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0063 is a Russian‑linked espionage threat actor aligned with APT28/Fancy Bear that targets government, diplomatic, and research institutions across Central Asia and Europe. It leverages macro‑enabled Office attachments to deliver the backdoors HATVIBE and CHERRYSPY, exploiting CVE‑2022‑38028 for privilege escalation and employing steganographic encryption to evade detection. The group exfiltrates credentials, documents, and media via HTTPS, USB, and cloud channels while maintaining persistence through scheduled tasks and mshta loaders.
Goals & Targeting
The strategic aim of UAC‑0063 is geopolitical espionage, collecting classified and operational data from government entities, diplomatic missions, scientific institutions, and critical infrastructure in Central Asia and Europe. By infiltrating key decision‑making bodies—particularly those concerning Ukraine, Kazakhstan, and Russia’s neighboring states—the actor seeks to support intelligence gathering for strategic planning, influence regional stability, and potentially back Russian state policy in the Indo‑Pacific and Balkans. The emphasis on privileged accounts, credential theft, mass data exfiltration, and persistence suggests a focus on long‑term information operations rather than short‑cycle financial gain.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0063 has been active since at least 2021, scaling from targeted attacks on Central Asian diplomatic and research bodies to a broader European footprint that includes Ukrainian government agencies, Russian allies, and international NGOs. Campaigns are orchestrated in stages: initial phishing emails using disguised word‑processing attachments, exploitation of known Windows privilege‑escalation CVEs, delivery of lightweight, obfuscated payloads that persist via scheduled tasks or run‑once mechanisms, and sustained data exfiltration over encrypted channels or removable media. The actor exhibits operational tempo conducive to long‑term surveillance rather than opportunistic disruption, with regular updates to C2 hosts and renewal of TLS certificates to preserve anonymity. While the group has a known association with APT28/Fancy Bear, recent evidence also suggests linkages to other GRU-linked units operating under different aliases (e.g., UAC‑0056, TAG‑110).
IOC Patterns
Recommended Actions
Confidence Assessment
Based on multiple independently corroborated reports, the evidence strongly supports that UAC-0063 is a Russian state‑aligned espionage group operating with capabilities consistent with APT28/Fancy Bear. The convergence of unique TTPs (CVE‑2022‑38028 exploitation, HATVIBE/CHERRYSPY backdoors, macro‑enabled phishing) and recurring attribution claims gives moderate‑to‑high confidence in the actor’s identity. However, detailed timelines, full campaign scope, and definitive attribution links remain incomplete; further investigations and indicators are required to refine risk assessments for specific targets.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
47
Tools
0
Campaigns
40
IOCs
0
Observed Data
11
Tactics