Also known as: UNC4221, UAC-0195, Winter Vivern to target, Synaptics worm, APT33, Curious Serpens, Elfin, Refined Kitten, SEABORGIUM, TA446, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, Sandworm, Seashell Blizzard, Infamous Chisel, UNC4057, Star Blizzard, RedMike, OPERATOR PANDA, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, SANDWORM RELIC
UAC‑0185 (alias UNC4221) is a sophisticated threat actor with a clear national infrastructure focus, primarily targeting Ukrainian defense and industrial entities since 2022. The group leverages credential theft from popular messaging platforms—Signal, Telegram, and WhatsApp—as well as proprietary military systems such as DELTA, TENETA, and Kropyva. Its initial access vectors include spear‑phishing campaigns that impersonate the Ukrainian Union of Industrialists and Entrepreneurs (UUIE), often embedding obfuscated JavaScript or malicious LNK shortcuts within ZIP attachments to drop loaders like SmokeLoader or Ande Loader. Once inside a target network, UAC‑0185 employs a layered approach: custom utilities such as MESHAGENT and UltraVNC provide remote‑access capabilities, while more widely used tools including Cobalt Strike beacons, CSharp‑Streamer‑RAT, Rhadamanthys, AnyDesk, and Remote Utilities enable lateral movement and persistence. The actors frequently exploit legacy VBA vulnerabilities (CVE‑2017‑0199 / CVE‑2017‑11882) to deliver malicious payloads, and they use process injection into explorer.exe for stealthy execution. They also perform credential theft from browsers, email clients (Outlook/Thunderbird), and FTP/file‑transfer applications. Beyond the Ukrainian context, the actor has extended its reach through malspam/malvertising campaigns that employ traffic distribution systems to deliver JavaScript downloaders, spawning a suite of RATs such as WasabiSeed, ScreenShotter, and AHK Bot. These tools have been observed in banking‑malware distributions (e.g., Astaroth) across Latin America, illustrating UAC‑0185’s adaptability and opportunistic expansion into broader financial targets.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0185, also known as UNC4221 and other aliases, is a Russia‑aligned threat actor that has been active since at least 2022. The group focuses on Ukrainian defense and industrial organizations, using credential theft via messaging apps, spear‑phishing, and exploitation of public‑facing applications to gain access. It deploys a mixture of custom remote‑access tools, backdoors, and ransomware‑like loaders for persistence and exfiltration.
Goals & Targeting
UAC‑0185 appears driven by a combination of financial gain and strategic influence. While its primary motivation is monetary—stealing credentials to monetize through ransomware or banking malware—it also focuses on high‑value defense infrastructure, suggesting potential espionage objectives. The group’s targeting profile demonstrates precision against critical national sectors in Ukraine and a broader threat landscape that includes finance, energy, and maritime domains worldwide.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0185’s activity reveals a consistent focus on Ukrainian defense infrastructure with sporadic global expansion. From early 2022, the group utilized spear‑phishing and credential‑theft via messaging apps, followed by lateral movement through custom remote‑access tools. Operational tempo has remained steady but adaptive: recent campaigns demonstrate use of malicious JavaScript downloaders that spawn a cascade of RATs, as well as banking‑malware deliveries (e.g., Astaroth) in Latin America linked to the same tool chain. Victim types include defense contractors, critical infrastructure providers (energy, telecommunications), financial services, and government agencies across multiple regions including the US, Europe, Asia, and the Middle East.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The analysis is based on multiple publicly reported sightings from CERT‑UA, FortiGuard Labs, and other industry reports, providing moderate confidence that UAC‑0185 is a Russia‑aligned actor focused on Ukrainian defense entities. However, gaps remain regarding the full extent of their tooling, timelines of earlier activity, and the complete scope of their global targets. Continuous monitoring and intelligence updates are recommended to refine attribution and operational understanding.
No campaigns linked yet.
No observed data linked yet.
49
Techniques
49
Tools
0
Campaigns
40
IOCs
0
Observed Data
12
Tactics