Also known as: STOCKSTAY, Secret Blizzard, VENOMOUS BEAR, APT-C-36, deliver malicious .url files, Blind Eagle, cybercrime, interaction-less, fully remote attacks
UAC‑0194 is a Russian advanced persistent threat that has been linked to Turla and operates primarily through complex spearphishing campaigns aimed at high-value public and private sector targets across multiple countries including Ukraine, the United States, Germany, and Brazil. Attack vectors commonly include malicious RDP configuration files (.rdp) and Web‑based .url attachments that trigger WebDAV requests upon user interaction. Once executed, a lightweight .NET downloader (STOCKSTAY.MARKETMAKER) is deployed to retrieve the full StockStay trojan from compromised file‑sharing services or vulnerable web sites. The StockStay backdoor is highly configurable; it can embed hard‑coded passwords or environment keying based on host identity, user name, or domain. It establishes a WebSocket C2 channel (e.g., wss://weatherdataai.theworkpc.com/ws) and supports multiple persistence mechanisms such as auto‑start execution, scheduled tasks, and malicious service creation. The malware suite includes associated Remote Access Trojans—Remcos, AsyncRAT, NjRAT—and encryption modules (HeartCrypt, PureCrypter) that obfuscate data exfiltration. UAC‑0194 demonstrates an ability to pivot quickly between exploitation techniques: after the Microsoft patch for CVE‑2024‑43451, the group shifted to exploiting CVE‑2025‑8088 via path‑traversal in malicious RAR archives. The actor also utilizes legitimate file‑sharing platforms (Google Drive, Bitbucket) for payload delivery and exfiltration of domain controller configuration files, making detection challenging. Overall, the threat actor is highly adaptable, leveraging zero days, social engineering, and custom-built malware to conduct espionage against strategic targets, often exploiting internal processes such as NTLM hash extraction via SMB.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0194, a Russian APT linked to Turla, targets government, defense, finance, and critical infrastructure sectors worldwide using sophisticated spearphishing campaigns that deliver a custom .NET downloader (STOCKSTAY.MARKETMAKER). The group exploits zero‑day vulnerabilities such as CVE‑2024‑43451 and CVE‑2025‑8088, delivers malicious RDP files and .url attachments, and then installs the StockStay backdoor to exfiltrate credentials and data via encrypted channels. Rapid adaptation after Microsoft patches and a focus on social engineering make UAC‑0194 a persistent espionage threat.
Goals & Targeting
UAC‑0194’s primary objective appears to be covert intelligence gathering, focused on government, defense, education, financial services, telecommunications, non‑profit, manufacturing, media, oil‑gas, and critical infrastructure entities worldwide. The actor tailors its payloads for precise environmental keying, enabling it to embed credentials tied to specific hosts or domains. Through relentless social engineering, the group achieves high breach rates in both public sector organizations (e.g., Ukrainian ministries) and private-sector institutions across Europe, Asia, Africa, Australia, and the Americas.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0194 has conducted a series of campaigns primarily against Ukrainian government and defense entities, but also targeting institutions in Germany, the U.S., Brazil, Colombia, and other countries. The actor employs a mix of spearphishing email attachments (.rdp), malicious links (.url), and exploit kits leveraging recent zero days to adapt its delivery methods post‑patch. Campaigns often involve a staged approach: initial compromise via phishing or CVE exploitation, downloader installation, backdoor persistence, credential harvesting, followed by encrypted data exfiltration. The group exhibits high operational tempo with rapid adaptation after vulnerability patches and a mix of both stealthy internal lateral movement and external exfiltration.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The intelligence linking UAC‑0194 to Turla and the StockStay backdoor chain is moderately high, supported by multiple independent reports highlighting identical malware signatures, delivery methods, and target profiles. However, gaps remain regarding precise attribution scope, internal structure of the actor, and full extent of its toolchain. Continuous monitoring and confirmation from additional evidence would increase confidence.
No campaigns linked yet.
No observed data linked yet.
44
Techniques
46
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics