Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0154

Also known as: BlackCat, Winter Vivern to target, Sandworm Team, Operation Cleaver, Shell Crew, WebMasters, KungFu Kittens, PinkPanther, a separate entity, APT28, VOLTZITE, for follow-on operations, Sandworm, Royal Ransomware, Gookee, kapuchin0, Guki, leaked the source code, shut the operation down

Description

UAC-0154 is a threat actor orchestrating the STARK#VORTEX phishing campaign, specifically targeting Ukraine’s military. They employ a Microsoft Help file containing obfuscated JavaScript as a lure, disguised as a manual for Pilot-in-Command Drones, to deliver the MerlinAgent malware. This PowerShell-based RAT is heavily obfuscated and downloads a payload from a remote server, enabling full control over compromised systems. The group initially targeted Ukrainian entities using military-themed documents sent via email to @ukr.net addresses.

Goals & Targeting

Targeted Sectors

Government
Financial services
Defense
Telecommunications
Education
Healthcare
Manufacturing
Media
Energy
Critical infrastructure
Non profit
Hospitality
Retail
Pharmaceutical
Aviation
Aerospace
Transportation
Information technology
Chemical
Think tank
Gaming
Mining
Legal services
Nuclear
Entertainment
Maritime
Construction
Oil gas
Utilities
Food agriculture

Targeted Countries / Regions

UA
CN
US
RU
IR
GB
AU
VN
IN
JP
PK
TW
IL
SA
DE
AE
PL
BY
SG
KR
KP
CA
TR
MX
ES
RO
FR
NG
IT
LB
AZ
KZ

AI Analysis

· 1 week ago

Executive Summary

UAC-0154 is a threat actor targeting Ukraine’s military through phishing campaigns using Microsoft Help files containing obfuscated JavaScript to deliver the MerlinAgent malware, a PowerShell-based remote access tool (RAT). Their activities include sending malicious emails with themed documents and leveraging command-and-control infrastructure to maintain persistence and execute malicious payloads.

Goals & Targeting

UAC-0154 appears to be targeting Ukraine's military sector, likely with strategic objectives aligned with espionage or disruption of national security operations. The group’s choice of targets indicates a focus on gaining access to classified or sensitive data related to military activities. Their sustained campaign against Ukrainian military personnel suggests a long-term effort to achieve their goals, possibly in coordination with broader adversarial interests.

Enhanced Description

UAC-0154 is identified as a threat actor conducting the STARK#VORTEX phishing campaign, specifically targeting military personnel in Ukraine. The group has been observed using Microsoft Help files that appear legitimate but contain obfuscated JavaScript designed to download and execute MerlinAgent malware. This RAT enables full system control and exfiltrates sensitive data. The initial targeting involved emails with military-themed document lures sent to @ukr.net addresses. UAC-0154 employs sophisticated techniques to avoid detection, including file obfuscation and command-and-control (C2) communication methods. Their activities suggest a focus on compromising military networks and extracting sensitive information or disrupting operations.

Key Capabilities

  • Phishing using spear-phishing emails
  • Obfuscation of malware for evasion
  • PowerShell-based remote access tools
  • Command-and-control infrastructure management
  • Military-themed document lures

MITRE ATT&CK Tactics

Stealing Sensitive Information (exfiltration)
Defense Evasion
Credential Access

ATT&CK Techniques

T1057
T1059.003
T1046
T1532
T1568

Software / Tooling

MerlinAgent RAT
Cobalt Strike (if used as per similar TTPs)
Obfuscation tools like UPX or other packers
Mimikatz-like credential dumping tools

Campaigns & Victims

UAC-0154 has demonstrated a persistent and targeted approach to compromising Ukrainian military networks. Their campaign patterns include the use of email phishing, obfuscated malicious documents, and RAT deployment for long-term access. The group appears to have operational persistence, as evidenced by their ongoing activities despite potential disruptions in their infrastructure.

IOC Patterns

  • Spear-phishing emails with military-themed documents
  • Obfuscated JavaScript within Microsoft Help files
  • C2 communication via HTTP or DNS requests
  • Presence of MerlinAgent RAT and associated PowerShell scripts
  • Network traffic indicative of remote access malware

Recommended Actions

  • Implement rigorous email filtering to detect spear-phishing attempts.
  • Monitor for obfuscated file activity and network anomalies linked to known C2 domains.
  • Deploy endpoint detection and response (EDR) solutions to identify malicious PowerShell activities.
  • Conduct regular user training on security awareness, particularly regarding military-themed phishing attempts.
  • Maintain up-to-date antivirus and threat detection software to block known malware variants.

Suggested Tags

APT
Espionage
Military Sector
Ukraine
Phishing

Confidence Assessment

High confidence in the identification of UAC-0154 as a persistent threat actor targeting Ukraine’s military. The group's TTPs are well-documented, but gaps remain regarding their exact affiliations and long-term strategic goals beyond immediate data exfiltration.

ATT&CK Techniques

Privilege Escalation
1 technique
Reconnaissance
1 technique

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. attack.mitre.org — Cited by web research for: Sandworm Team
  2. attack.mitre.org — Cited by web research for: Sandworm
  3. unit42.paloaltonetworks.com — Cited by web research for: Royal Ransomware
  4. www.bitdefender.com — Cited by web research for: PowerShell
  5. www.huntress.com — Cited by web research for: Beacon

Intel Summary

40

Techniques

40

Tools

0

Campaigns

38

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting
APT
Espionage
Military Sector
Ukraine

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
China (CN)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.