Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0063

Also known as: APT28, TAG-110, including government entities, diplomatic missions, CHERRYSPY, CherrySpy, APT34, Earth Preta, Stately Taurus, COLDRIVER, SEABORGIUM, Star Blizzard, Blue Callisto, BlueCharlie, Storm-0978, Tropical Scorpius, UNC2596, UAC-0056, UNC2589, EmberBear, LorecBear, Lorec53, TA471, Fancy Bear, Forest Blizzard, Sofacy, APT29, Cozy Bear, Nobelium, Snake, UAC-0020, Operation C-Major, Mythic Leopard, ProjectM, APT36, Earth Karkaddan, APT-C-23, Desert Falcons, Two-tailed Scorpion, PROMETHIUM

Description

UAC‑0063 operates as an advanced persistent threat, executing complex supply‑chain and in‑org infiltration campaigns that are hallmarks of APT28’s operational tempo. At the initial access phase, adversaries use spear‑phishing emails adorned with macro‑enabled .dotm documents to deploy backdoor loaders such as HATVIBE (HTA wrapper) and CHERRYSPY (a Python‑based implant). Once resident, the malware exfiltrates information through multiple vectors: encrypted HTTP PUT/GET traffic, USB‑based extraction via PyPlunderPlug, and optional cloud uploads. Privilege escalation is routinely achieved with the CVE‑2022‑38028 Windows kernel vulnerability and other abuse‑elevation mechanisms, allowing lateral movement across office networks. The actor’s toolset exhibits a mix of proprietary code and open‑source components. HATVIBE integrates obfuscated VBScript that manipulates registry keys (AccessVBOM) and schedules persistently via Task Scheduler. CHERRYSPY incorporates keylogging, clipboard monitoring through LOGPIE, screen capture with the Python "mss" library, and credential dumping from local stores and browsers. Both implants communicate using AES‑encrypted JSON messages, often prefixed with hex markers to bypass inspection. In addition, UAC‑0063 deploys ancillary tools such as Authentic Antics ransomware during opportunistic attacks. Defensive evasion is a core focus: the malware employs steganography to hide its code inside innocuous images or documents, uses XOR‑encoded URLs, and renews TLS certificates on compromised domains. The attackers also exploit public‑facing services (e.g., HFS HTTP File Server) for initial compromise of remote targets. Overall, UAC‑0063 demonstrates a sophisticated, multi‑stage attack lifecycle that blends advanced malware development with opportunistic exploitation of known vulnerabilities.

Goals & Targeting

Targeted Sectors

Government
Defense
Telecommunications
Financial services
Education
Non profit
Healthcare
Energy
Manufacturing
Media
Think tank
Critical infrastructure
Aviation
Aerospace
Pharmaceutical
Hospitality
Chemical
Transportation
Information technology
Retail
Maritime
Legal services
Oil gas
Mining
Gaming
Nuclear
Entertainment
Utilities
Construction

Targeted Countries / Regions

RU
US
CN
UA
KZ
IL
DE
AE
GB
IN
VN
RO
PK
IR
JP
KR
BY
TW
SA
NL
PL
TR
AU
LB
FR
SG
IT
MX
ES
KP
CA
IQ
NG
AZ

AI Analysis

Grounded in web research
· analyzed in 54 chunks · 20 hours ago

Executive Summary

UAC‑0063 is a Russian‑linked espionage threat actor aligned with APT28/Fancy Bear that targets government, diplomatic, and research institutions across Central Asia and Europe. It leverages macro‑enabled Office attachments to deliver the backdoors HATVIBE and CHERRYSPY, exploiting CVE‑2022‑38028 for privilege escalation and employing steganographic encryption to evade detection. The group exfiltrates credentials, documents, and media via HTTPS, USB, and cloud channels while maintaining persistence through scheduled tasks and mshta loaders.

Goals & Targeting

The strategic aim of UAC‑0063 is geopolitical espionage, collecting classified and operational data from government entities, diplomatic missions, scientific institutions, and critical infrastructure in Central Asia and Europe. By infiltrating key decision‑making bodies—particularly those concerning Ukraine, Kazakhstan, and Russia’s neighboring states—the actor seeks to support intelligence gathering for strategic planning, influence regional stability, and potentially back Russian state policy in the Indo‑Pacific and Balkans. The emphasis on privileged accounts, credential theft, mass data exfiltration, and persistence suggests a focus on long‑term information operations rather than short‑cycle financial gain.

Enhanced Description

Key Capabilities

  • Privilege escalation via CVE-2022-38028
  • Defense evasion using steganography and encryption
  • Spear-phishing with macro-enabled .dotm Office documents
  • Use of HATVIBE backdoor for data exfiltration
  • Use of CHERRYSPY (DownExPyer) for credential theft and logon monitoring
  • Keylogging and clipboard monitoring via LOGPIE
  • Screen capture and audio recording
  • USB-based data exfiltration with PyPlunderPlug
  • Process injection into cmd.exe / Windows-command shell
  • Scheduled task creation for persistence
  • MShta execution of HTA loaders
  • Encrypted HTTP PUT/GET C2 communication (AES)
  • Compressed file archives (<16 MB) for exfil
  • File deletion post-exfil
  • Python-based implant deployment and command execution
  • Credential dumping from web browsers and Windows Credential Manager
  • Exploit of public-facing software vulnerabilities (HFS, Rejetto)
  • Discovery of shared folders and removable media

MITRE ATT&CK Tactics

Privilege Escalation
Defense Evasion
Initial Access
Execution
Persistence
Discovery
Collection
Credential Access
Exfiltration
Command and Control
Impact
Lateral Movement

ATT&CK Techniques

T1053.005
T1113
T1033
T1027.013
T1123
T1561.001
T1547
T1204.002
T1573.001
T1087.001
T1566.001
T1120
T1082
T1071
T1106
T1005
T1190
T1555
T1036
T1055
T1548
T1059
T1583.003
T1102
T1218.005
T1204
T1057
T1566
T1559
T1027
T1203
T1573.002
T1059.003
T1189
T1071.001
T1059.005
T1529

Software / Tooling

HATVIBE
CHERRYSPY (DownEx/DownExPyer)
LOGPIE keylogger
PyPlunderPlug USB exfiltration tool
Cobalt Strike beacon
Authentic Antics ransomware
Python-based implant framework
mshta loader (HTA)

Campaigns & Victims

UAC‑0063 has been active since at least 2021, scaling from targeted attacks on Central Asian diplomatic and research bodies to a broader European footprint that includes Ukrainian government agencies, Russian allies, and international NGOs. Campaigns are orchestrated in stages: initial phishing emails using disguised word‑processing attachments, exploitation of known Windows privilege‑escalation CVEs, delivery of lightweight, obfuscated payloads that persist via scheduled tasks or run‑once mechanisms, and sustained data exfiltration over encrypted channels or removable media. The actor exhibits operational tempo conducive to long‑term surveillance rather than opportunistic disruption, with regular updates to C2 hosts and renewal of TLS certificates to preserve anonymity. While the group has a known association with APT28/Fancy Bear, recent evidence also suggests linkages to other GRU-linked units operating under different aliases (e.g., UAC‑0056, TAG‑110).

IOC Patterns

  • hash-md5 of malicious documents and payloads
  • malicious domain names used for C2 (e.g., lanmangraphics.com)
  • IPv4 addresses linked to C2 servers
  • .logs files with archiving size <16 MB
  • Python scripts in %LOCALAPPDATA% such as crashreporting.py
  • Scheduled task names like Application\SynchronizeTime or Settings\ServiceDispatch
  • Registry key AccessVBOM modification for Office macro execution
  • mshta.exe processes running HTA loaders
  • Encrypted AES C2 payloads with hex prefixes
  • USB device enumeration and data transfer via PyPlunderPlug
  • File deletion events immediately after upload
  • TLS certificate renewal timestamps

Recommended Actions

  • Apply patches for CVE-2022-38028 and related Windows kernel updates promptly.
  • Configure email gateways to block or quarantine macro-enabled Office documents (.dotm/.doc) and enable attachment sandboxing.
  • Implement EDR/XDR solutions with detection rules for HATVIBE, CHERRYSPY, LOGPIE, PyPlunderPlug and Cobalt Strike signatures.
  • Block outbound HTTPS traffic to known malicious domains and IPs used by UAC-0063’s C2 infrastructure.
  • Enforce strict macro security policies (disable macros by default; enable only digitally signed scripts).
  • Monitor for creation of scheduled tasks with atypical names and associated mshta execution; investigate anomalies.
  • Restrict execution of unknown Python binaries in %APPDATA% and monitor subprocess.Popen calls. Implement keylogging and screen‑capture detection capabilities; configure alerts for suspicious clipboard activity via LOGPIE. Deploy network segmentation and micro‑segmentation between government and research networks to limit lateral movement. Enforce MFA on privileged accounts, lock out after repeated failed logins and audit credential dumping events. Utilize DLP policies aimed at preventing exfiltration of documents >250 KB or media files; set alerts for large .png uploads. Regularly review and harden registry keys such as AccessVBOM; revoke unnecessary permissions on Office applications. Conduct periodic threat hunting for steganographic content inside images, PDFs, or Office documents; use image‑analysis tools. Maintain a CVE‑tracking system to detect public‑facing software exploits (e.g., HFS, Rejetto) and patch accordingly. Document and mitigate any discovered data deletion patterns that follow successful exfiltration events.

Confidence Assessment

Based on multiple independently corroborated reports, the evidence strongly supports that UAC-0063 is a Russian state‑aligned espionage group operating with capabilities consistent with APT28/Fancy Bear. The convergence of unique TTPs (CVE‑2022‑38028 exploitation, HATVIBE/CHERRYSPY backdoors, macro‑enabled phishing) and recurring attribution claims gives moderate‑to‑high confidence in the actor’s identity. However, detailed timelines, full campaign scope, and definitive attribution links remain incomplete; further investigations and indicators are required to refine risk assessments for specific targets.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 IPv4 Address 2 Domain 7 MD5 Hash 6

References

  1. www.bitdefender.com — Cited by web research for: TAG-110
  2. www.eset.com — Cited by web research for: APT34
  3. attack.mitre.org — Cited by web research for: T1548
  4. www.recordedfuture.com — Cited by web research for: T1583.003
  5. attack.mitre.org — Cited by web research for: Akira
  6. apt.etda.or.th — Cited by web research for: DealersChoice
  7. businessinsights.bitdefender.com — Cited by web research for: Oil Gas

Intel Summary

40

Techniques

47

Tools

0

Campaigns

40

IOCs

0

Observed Data

11

Tactics

Tags

APT
Phishing
Backdoor / C2
Government Targeting
espionage
cyber espionage
government targeting
Central Asia

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.