Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0185

Also known as: UNC4221, UAC-0195, Winter Vivern to target, Synaptics worm, APT33, Curious Serpens, Elfin, Refined Kitten, SEABORGIUM, TA446, APT-C-35, Origami Elephant, Brainworm, APT32, Salt Typhoon, FamousSparrow, GhostEmperor, UNC2286, Deed RAT, Core Werewolf, Storm-0978, Tropical Scorpius, UNC2596, UNC4210, Asylum Ambuscade, Guildma, Sandworm, Seashell Blizzard, Infamous Chisel, UNC4057, Star Blizzard, RedMike, OPERATOR PANDA, Quedagh, VOODOO BEAR, TEMP.Noble, IRON VIKING, G0034, ELECTRUM, TeleBots, IRIDIUM, Blue Echidna, FROZENBARENTS, UAC-0113, UAC-0082, APT44, SANDWORM RELIC

Description

UAC‑0185 (alias UNC4221) is a sophisticated threat actor with a clear national infrastructure focus, primarily targeting Ukrainian defense and industrial entities since 2022. The group leverages credential theft from popular messaging platforms—Signal, Telegram, and WhatsApp—as well as proprietary military systems such as DELTA, TENETA, and Kropyva. Its initial access vectors include spear‑phishing campaigns that impersonate the Ukrainian Union of Industrialists and Entrepreneurs (UUIE), often embedding obfuscated JavaScript or malicious LNK shortcuts within ZIP attachments to drop loaders like SmokeLoader or Ande Loader. Once inside a target network, UAC‑0185 employs a layered approach: custom utilities such as MESHAGENT and UltraVNC provide remote‑access capabilities, while more widely used tools including Cobalt Strike beacons, CSharp‑Streamer‑RAT, Rhadamanthys, AnyDesk, and Remote Utilities enable lateral movement and persistence. The actors frequently exploit legacy VBA vulnerabilities (CVE‑2017‑0199 / CVE‑2017‑11882) to deliver malicious payloads, and they use process injection into explorer.exe for stealthy execution. They also perform credential theft from browsers, email clients (Outlook/Thunderbird), and FTP/file‑transfer applications. Beyond the Ukrainian context, the actor has extended its reach through malspam/malvertising campaigns that employ traffic distribution systems to deliver JavaScript downloaders, spawning a suite of RATs such as WasabiSeed, ScreenShotter, and AHK Bot. These tools have been observed in banking‑malware distributions (e.g., Astaroth) across Latin America, illustrating UAC‑0185’s adaptability and opportunistic expansion into broader financial targets.

Goals & Targeting

Targeted Sectors

Defense
Government
Financial services
Manufacturing
Telecommunications
Energy
Pharmaceutical
Transportation
Critical infrastructure
Construction
Education
Healthcare
Media
Food agriculture
Chemical
Retail
Non profit
Maritime
Mining
Aviation

Targeted Countries / Regions

RU
UA
DE
IN
PK
CN
IR
US
TR
KP
KR
JP
IT
VN
BR
TW
SA
AE
FR
CA
AU
GB
BY

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UAC‑0185, also known as UNC4221 and other aliases, is a Russia‑aligned threat actor that has been active since at least 2022. The group focuses on Ukrainian defense and industrial organizations, using credential theft via messaging apps, spear‑phishing, and exploitation of public‑facing applications to gain access. It deploys a mixture of custom remote‑access tools, backdoors, and ransomware‑like loaders for persistence and exfiltration.

Goals & Targeting

UAC‑0185 appears driven by a combination of financial gain and strategic influence. While its primary motivation is monetary—stealing credentials to monetize through ransomware or banking malware—it also focuses on high‑value defense infrastructure, suggesting potential espionage objectives. The group’s targeting profile demonstrates precision against critical national sectors in Ukraine and a broader threat landscape that includes finance, energy, and maritime domains worldwide.

Enhanced Description

Key Capabilities

  • Targeted attacks on Ukrainian defense and industrial organizations
  • Use of malspam/malvertising to redirect victims to traffic distribution systems
  • Email thread hijacking for persistence within email chains
  • Deployment of malicious JavaScript downloaders delivering WasabiSeed, ScreenShotter, AHK Bot
  • Resident backdoors such as Cobalt Strike beacons, CSharp‑Streamer‑RAT, Rhadamanthys, AnyDesk, Remote Utilities
  • Spear‑phishing with obfuscated JavaScript in ZIP attachments containing LNK shortcuts abusing mshta.exe
  • Exploitation of legacy Microsoft Excel VBA vulnerabilities (CVE‑2017‑0199 and CVE‑2017‑11882) to deploy loaders like Ande Loader and SmokeLoader
  • Persistence via process injection into explorer.exe
  • Credential theft from browsers, email clients, FTP, and file transfer applications

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Credential Access
Command and Control
Defense Evasion
Discovery

ATT&CK Techniques

T1548
T1548.002
T1566
T1566.001
T1172
T1204
T1140
T1105
T1055
T1063
T1071
T1037
T1560.001
T1132.001
T1129
T1123
T1133
T1560.003
T1559.002
T1559.001
T1135
T1558.004
T1190
T1560.002
T1518.002
T1550
T1560
T1610
T1134.002
T1125
T1558.001
T1127.003
T1559.003
T1134.001
T1134.003
T1134.004
T1134.005
T1059.013
T1127.001
T1127.002
T1059.003
T1132.002
T1498
T1134
T1550.001
T1124
T1490
T1127

Software / Tooling

MESHAGENT
UltraVNC
Cobalt Strike
CSharp‑Streamer‑RAT
Rhadamanthys
AnyDesk
Remote Utilities
WasabiSeed
ScreenShotter
AHK Bot
SmokeLoader
Ande Loader

Campaigns & Victims

UAC‑0185’s activity reveals a consistent focus on Ukrainian defense infrastructure with sporadic global expansion. From early 2022, the group utilized spear‑phishing and credential‑theft via messaging apps, followed by lateral movement through custom remote‑access tools. Operational tempo has remained steady but adaptive: recent campaigns demonstrate use of malicious JavaScript downloaders that spawn a cascade of RATs, as well as banking‑malware deliveries (e.g., Astaroth) in Latin America linked to the same tool chain. Victim types include defense contractors, critical infrastructure providers (energy, telecommunications), financial services, and government agencies across multiple regions including the US, Europe, Asia, and the Middle East.

IOC Patterns

  • Randomly generated domain names used by traffic distribution systems
  • Malspam/malvertising campaigns with embedded downloaders
  • Email thread hijacking techniques for persistence
  • ZIP attachments containing malicious LNK shortcuts abusing mshta.exe
  • Obfuscated JavaScript code for command-and-control
  • Exploitation of CVE‑2017‑0199 / CVE‑2017‑11882 via VBA in Microsoft Excel
  • VBS scripts used to drop loaders like Ande Loader or SmokeLoader
  • Process injection into explorer.exe for persistence and evasion
  • Credential theft plugins targeting browsers, Outlook, Thunderbird, FileZilla, WinSCP

Recommended Actions

  • Apply all critical patches including CVE‑2017‑0199 and CVE‑2017‑11882 on all endpoints
  • Deploy detection rules aligned with T1548 (UAC bypass) and process injection indicators (T1055)
  • Block malicious domain names associated with traffic distribution systems identified in IOC patterns
  • Enhance email filtering to detect spear‑phishing attachments, LNK shortcuts and obfuscated JavaScript
  • Monitor mshta.exe usage and enforce application whitelisting for PowerShell & VBScript
  • Detect installation of remote‑access tools such as AnyDesk and Remote Utilities on corporate networks
  • Implement least‑privilege policies and MFA for critical accounts, especially messaging app integrations
  • Deploy endpoint detection and response solutions that flag credential-stealer activity in browsers and file‑transfer apps

Suggested Tags

Russia
Ukraine
Financial-Motivation
Defence-Industry-Targeting
Messaging-App-Exploitation
Malspam
Malvertising
VBA-CVE-2017
Credential-Theft
Remote-Access-Tools
Obfuscated-JavaScript
Process-Injection
Command-and-Control
Cobalt-Strike
AnyDesk
Rhubarz

Confidence Assessment

The analysis is based on multiple publicly reported sightings from CERT‑UA, FortiGuard Labs, and other industry reports, providing moderate confidence that UAC‑0185 is a Russia‑aligned actor focused on Ukrainian defense entities. However, gaps remain regarding the full extent of their tooling, timelines of earlier activity, and the complete scope of their global targets. Continuous monitoring and intelligence updates are recommended to refine attribution and operational understanding.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

Filename 5 Domain 15

References

  1. ics-cert.kaspersky.com — Cited by web research for: APT-C-35
  2. cloud.google.com — Cited by web research for: Sandworm
  3. attack.mitre.org — Cited by web research for: T1518.002
  4. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  5. https://cert.gov.ua/alert#12414 — Cited by AI analysis.
  6. https://fortiguard.com/research/report/a-staroth — Cited by AI analysis.

Intel Summary

49

Techniques

49

Tools

0

Campaigns

40

IOCs

0

Observed Data

12

Tactics

Tags

Critical Infrastructure
Phishing
Data Exfiltration
Government Targeting
APT
espionage
Ukraine-focused
defense-sector
custom-malware
Russia
Ukraine
Financial-Motivation
Defence-Industry-Targeting
Messaging-App-Exploitation
Malspam
Malvertising
VBA-CVE-2017
Credential-Theft
Remote-Access-Tools
Obfuscated-JavaScript
Process-Injection
Command-and-Control
Cobalt-Strike
AnyDesk
Rhubarz

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Russia (RU)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.