Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0194

Also known as: STOCKSTAY, Secret Blizzard, VENOMOUS BEAR, APT-C-36, deliver malicious .url files, Blind Eagle, cybercrime, interaction-less, fully remote attacks

Description

UAC‑0194 is a Russian advanced persistent threat that has been linked to Turla and operates primarily through complex spearphishing campaigns aimed at high-value public and private sector targets across multiple countries including Ukraine, the United States, Germany, and Brazil. Attack vectors commonly include malicious RDP configuration files (.rdp) and Web‑based .url attachments that trigger WebDAV requests upon user interaction. Once executed, a lightweight .NET downloader (STOCKSTAY.MARKETMAKER) is deployed to retrieve the full StockStay trojan from compromised file‑sharing services or vulnerable web sites. The StockStay backdoor is highly configurable; it can embed hard‑coded passwords or environment keying based on host identity, user name, or domain. It establishes a WebSocket C2 channel (e.g., wss://weatherdataai.theworkpc.com/ws) and supports multiple persistence mechanisms such as auto‑start execution, scheduled tasks, and malicious service creation. The malware suite includes associated Remote Access Trojans—Remcos, AsyncRAT, NjRAT—and encryption modules (HeartCrypt, PureCrypter) that obfuscate data exfiltration. UAC‑0194 demonstrates an ability to pivot quickly between exploitation techniques: after the Microsoft patch for CVE‑2024‑43451, the group shifted to exploiting CVE‑2025‑8088 via path‑traversal in malicious RAR archives. The actor also utilizes legitimate file‑sharing platforms (Google Drive, Bitbucket) for payload delivery and exfiltration of domain controller configuration files, making detection challenging. Overall, the threat actor is highly adaptable, leveraging zero days, social engineering, and custom-built malware to conduct espionage against strategic targets, often exploiting internal processes such as NTLM hash extraction via SMB.

Goals & Targeting

Targeted Sectors

Government
Defense
Education
Financial services
Telecommunications
Non profit
Manufacturing
Media
Oil gas
Critical infrastructure

Targeted Countries / Regions

UA
AE
RU
IR
CN
DE
TW
US
FR
VN
NG
AU
SA
LB
PL
NL
IT

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 1 day ago

Executive Summary

UAC‑0194, a Russian APT linked to Turla, targets government, defense, finance, and critical infrastructure sectors worldwide using sophisticated spearphishing campaigns that deliver a custom .NET downloader (STOCKSTAY.MARKETMAKER). The group exploits zero‑day vulnerabilities such as CVE‑2024‑43451 and CVE‑2025‑8088, delivers malicious RDP files and .url attachments, and then installs the StockStay backdoor to exfiltrate credentials and data via encrypted channels. Rapid adaptation after Microsoft patches and a focus on social engineering make UAC‑0194 a persistent espionage threat.

Goals & Targeting

UAC‑0194’s primary objective appears to be covert intelligence gathering, focused on government, defense, education, financial services, telecommunications, non‑profit, manufacturing, media, oil‑gas, and critical infrastructure entities worldwide. The actor tailors its payloads for precise environmental keying, enabling it to embed credentials tied to specific hosts or domains. Through relentless social engineering, the group achieves high breach rates in both public sector organizations (e.g., Ukrainian ministries) and private-sector institutions across Europe, Asia, Africa, Australia, and the Americas.

Enhanced Description

Key Capabilities

  • Deploys spearphishing emails with malicious RDP (.rdp) attachments
  • Uses a .NET downloader (STOCKSTAY.MARKETMAKER) to fetch the StockStay backdoor
  • Exploits zero‑day vulnerabilities such as CVE-2024-43451 and CVE-2025-8088 for initial access
  • Delivers malicious .rar archives exploiting WinRAR path traversal
  • Employs .url files that trigger WebDAV requests upon user interaction
  • Uses legitimate hosting services (Google Drive, Dropbox, Bitbucket) for payload delivery
  • Installs StockStay with hard‑coded passwords or environment‑based keying
  • Establishes encrypted WebSocket C2 channels
  • Exfiltrates data and credentials via encrypted configuration modules (HeartCrypt, PureCrypter)
  • Performs NTLM hash extraction over SMB
  • Adapts quickly after patches to new exploitation vectors

MITRE ATT&CK Tactics

Initial Access
Discovery
Command and Control
Execution
Persistence
Credential Access
Defense Evasion
Exfiltration

ATT&CK Techniques

T1566.001
T1021.004
T1105
T1087.001
T1071.001
T1047
T1113
T1033
T1583
T1003
T1543
T1547
T1007
T1053
T1140
T1190
T1555
T1567
T1036
T1218
T1560
T1112
T1595
T1548
T1016
T1090
T1059
T1482
T1049
T1584
T1608
T1204
T1057
T1210
T1098
T1566
T1574
T1027
T1588
T1189
T1134
T1018

Software / Tooling

STOCKSTAY
STOCKSTAY.MARKETMAKER
KAZUAR
Turla
WILDDAY
DIAMONDBACK
NjRAT
AsyncRAT
Remcos
HeartCrypt
PureCrypter
Mimikatz
LaZagne

Campaigns & Victims

UAC‑0194 has conducted a series of campaigns primarily against Ukrainian government and defense entities, but also targeting institutions in Germany, the U.S., Brazil, Colombia, and other countries. The actor employs a mix of spearphishing email attachments (.rdp), malicious links (.url), and exploit kits leveraging recent zero days to adapt its delivery methods post‑patch. Campaigns often involve a staged approach: initial compromise via phishing or CVE exploitation, downloader installation, backdoor persistence, credential harvesting, followed by encrypted data exfiltration. The group exhibits high operational tempo with rapid adaptation after vulnerability patches and a mix of both stealthy internal lateral movement and external exfiltration.

IOC Patterns

  • malicious .rdp attachment
  • encrypted configuration file tied to domain name
  • ZIP download from compromised Ukrainian state regulator website
  • WebSocket C2 endpoint wss://weatherdataai.theworkpc.com/ws
  • CVE-2025-8088 path traversal in .rar archives
  • CVE-2024-43451 exploitation via WebDAV requests
  • .url file triggering WebDAV requests
  • malicious file names such as StockMarketView.exe, 2025.hta, DiplomacyEduAI.msi
  • email address support@microsoftonlines.com used for spearphishing

Recommended Actions

  • Block or quarantine emails containing RDP (.rdp) attachment files
  • Implement advanced email filtering and attachment sandboxing to detect .NET downloaders (STOCKSTAY.MARKETMAKER)
  • Apply patches for CVE-2024-43451 and CVE-2025-8088 immediately across all Windows environments
  • Monitor outbound WebSocket traffic on non‑standard ports, especially wss:// connections
  • Audit and harden domain controller configurations to prevent unauthorized config deployments
  • Use threat‑intel feeds for known malicious domains (e.g., TEMP.Zagros) and URLs
  • Enforce multi‑factor authentication to mitigate credential theft
  • Employ endpoint detection systems capable of detecting .NET downloader signatures and encrypted RAT variants (HeartCrypt, PureCrypter)
  • Maintain continuous monitoring of security events and user activity
  • Conduct phishing awareness training focusing on RDP attachments and malicious links

Suggested Tags

APT
Turla
StockStay
KAZUAR
Phishing
Malicious RDP Attachments
WebSocket C2
Encrypted Configuration
Ukrainian Targets
Spearphishing Link
CVE Exploitation
Remote Access Trojan
Targeted Government Organizations
Colombian Institutions
Social Engineering
File‑Based Malware Delivery
Public‑Sector Targeting
Private‑Sector Targeting

Confidence Assessment

The intelligence linking UAC‑0194 to Turla and the StockStay backdoor chain is moderately high, supported by multiple independent reports highlighting identical malware signatures, delivery methods, and target profiles. However, gaps remain regarding precise attribution scope, internal structure of the actor, and full extent of its toolchain. Continuous monitoring and confirmation from additional evidence would increase confidence.

ATT&CK Techniques

Defense impairment
1 technique
Exfiltration
1 technique
Privilege Escalation
1 technique
Reconnaissance
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Domain 7 Filename 10 SHA-256 Hash 3

References

  1. cloud.google.com — Cited by web research for: STOCKSTAY
  2. research.checkpoint.com — Cited by web research for: APT-C-36
  3. www.kaspersky.com — Cited by web research for: interaction-less
  4. attack.mitre.org — Cited by web research for: T1583
  5. attack.mitre.org — Cited by web research for: T1087

Intel Summary

44

Techniques

46

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Tags

Critical Infrastructure
Phishing
Zero-Day Exploitation
Backdoor / C2
APT
Turla
StockStay
KAZUAR
Malicious RDP Attachments
WebSocket C2
Encrypted Configuration
Ukrainian Targets
Spearphishing Link
CVE Exploitation
Remote Access Trojan
Targeted Government Organizations
Colombian Institutions
Social Engineering
File‑Based Malware Delivery
Public‑Sector Targeting
Private‑Sector Targeting

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.