Also known as: Patchwork, Winter Vivern to target, UAC-0102 created a, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Winos 4.0, ALPHV, GreenCube, UNC3707, backdoors
UAC‑0102, also referred in some reports as GreenCube or UNC2452, operates with a pronounced emphasis on stealthy credential theft via phishing vectors. Its methodology centers on crafting deceptive email messages that embed HTML files; when opened, these attachments direct the user’s browser to a spoofed login page mimicking legitimate Ukrainian .NET portals. The stolen authentication data is then exfiltrated back to the actor’s infrastructure. Security researchers have identified a suite of Sigma detection rules that map the campaign’s indicators to MITRE ATT&CK techniques, particularly User Execution (T1204.001) and Phishing with Malicious Links or Attachments (T1566.001/002). Publicly available IOCs from CERT‑UA include malicious domain names such as TEMP.Veles and TEMP.Zagros, as well as IP addresses associated with known command‑and‑control servers. While UAC‑0102’s catalog of capabilities is limited in public disclosures, analysts have linked the actor to a broader network of threats—including Sandworm Team, APT28, and other state‑sponsored espionage entities—suggesting possible shared tooling or infrastructure. Nevertheless, the primary operational footprint remains the initial credential gathering via email-based social engineering. The group’s persistence in targeted campaigns against Ukrainian institutions and its expansion into additional sectors underscores a strategic geopolitical aim: to acquire actionable intelligence that can influence policy, commerce, and national security across a broad array of industries.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0102 is a covert espionage actor primarily targeting Ukrainian .NET users through spear‑phishing campaigns that employ malicious HTML attachments, which redirect victims to counterfeit authentication portals designed to harvest credentials. The group’s operations are low‑profile but strategically focused on gathering sensitive information from government and critical infrastructure entities across multiple countries.
Goals & Targeting
UAC‑0102 is driven by classic espionage objectives—stealing privileged credentials to gain unauthorized access to government, defense, energy, and critical infrastructure systems. By focusing on Ukraine’s .NET ecosystem, the actor exploits widespread use of legacy platforms vulnerable to phishing exploitation. The wide-ranging list of targeted countries—including Russia, China, the United Kingdom, and others—reflects a transnational strategy aimed at acquiring high‑value political and commercial intelligence that can support geopolitical objectives or state‑backed research agendas. Typical victims are mid‑to‑large organizations with public web portals, IT service providers, and private sector entities whose digital identities may provide access to broader networks. Key Capabilities:
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0102 operates with a disciplined yet low‑profile cadence, launching periodic spear‑phishing waves that target high‑profile Ukrainian institutions before extending reach to other geopolitical hotspots. Analysts have noted the actor’s modular approach—deploying additional capabilities once initial footholds are achieved—though concrete evidence of lateral movement or persistence remains scarce in public reports. The group leverages publicly documented IOCs and community‑derived Sigma rules, indicating an intent to blend with broad threat hunting frameworks. Historical links to other pro‑state groups suggest the potential for shared infrastructure or attack tooling, yet public attribution is ambiguous. IOC Patterns:
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The assessment is based primarily on a single public source (Malpedia) and the CERT‑UA detection notes. Attribution remains speculative due to overlapping aliases with known state‑backed groups, and many technical details about deeper capabilities are missing from open‑source disclosures. The list of MITRE techniques includes a wide range of behaviors that may not all be actively employed by UAC‑0102; hence we conservatively highlight core phishing and credential‑harvest tactics. Further evidence—such as malware samples, real‑time IOC feeds, or corroborative reports—would improve confidence in the actor’s full operational profile. sources":["https://malpedia.caad.fkie.fraunhofer.de/actor/uac-0102","https://attack.mitre.org/techniques/T1204/001/","UAC‑0102 Phishing Attack Detection: Hackers Steal Authentication ... (CERT‑UA)"]}
No campaigns linked yet.
No observed data linked yet.
46
Techniques
45
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics