Also known as: BlackCat, Winter Vivern to target, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Sandworm, Royal Ransomware, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down
UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military. They employ a Microsoft Help file containing obfuscated JavaScript as a lure, disguised as a manual for Pilot-in-Command Drones, to deliver the MerlinAgent malware. This PowerShell-based RAT is heavily obfuscated and downloads a payload from a remote server, enabling full control over compromised systems. The group initially targeted Ukrainian entities using military-themed documents sent via email to @ukr.net addresses.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC-0154 is a threat actor targeting Ukraine’s military through phishing campaigns using Microsoft Help files containing obfuscated JavaScript to deliver the MerlinAgent malware, a PowerShell-based remote access tool (RAT). Their activities include sending malicious emails with themed documents and leveraging command-and-control infrastructure to maintain persistence and execute malicious payloads.
Goals & Targeting
UAC-0154 appears to be targeting Ukraine's military sector, likely with strategic objectives aligned with espionage or disruption of national security operations. The group’s choice of targets indicates a focus on gaining access to classified or sensitive data related to military activities. Their sustained campaign against Ukrainian military personnel suggests a long-term effort to achieve their goals, possibly in coordination with broader adversarial interests.
Enhanced Description
UAC-0154 is identified as a threat actor conducting the STARK#VORTEX phishing campaign, specifically targeting military personnel in Ukraine. The group has been observed using Microsoft Help files that appear legitimate but contain obfuscated JavaScript designed to download and execute MerlinAgent malware. This RAT enables full system control and exfiltrates sensitive data. The initial targeting involved emails with military-themed document lures sent to @ukr.net addresses. UAC-0154 employs sophisticated techniques to avoid detection, including file obfuscation and command-and-control (C2) communication methods. Their activities suggest a focus on compromising military networks and extracting sensitive information or disrupting operations.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0154 has demonstrated a persistent and targeted approach to compromising Ukrainian military networks. Their campaign patterns include the use of email phishing, obfuscated malicious documents, and RAT deployment for long-term access. The group appears to have operational persistence, as evidenced by their ongoing activities despite potential disruptions in their infrastructure.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
High confidence in the identification of UAC-0154 as a persistent threat actor targeting Ukraine’s military. The group's TTPs are well-documented, but gaps remain regarding their exact affiliations and long-term strategic goals beyond immediate data exfiltration.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
38
IOCs
0
Observed Data
13
Tactics