Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Ukrainian Cyber Alliance

Ukrainian Cyber Alliance

TLP:CLEAR
Active

Also known as: UCA, tracked as, social media, BlackCat, AlphaVM, AlphaV, ALPHV, Cozy Bear, Cozy Duke, Pawn Storm, Fancy Bear, Tsar Team

Description

Ukrainian Cyber Alliance has emerged as a sophisticated hacktivist collective operating from or against Ukrainian interests. The group’s capabilities center on exploiting widely known but heavily mitigated vulnerabilities—most notably the Confluence zero‑day (CVE-2023-22515) and Zoho ManageEngine ADSelfService Plus flaw (CVE‑2021‑40539)—to achieve initial access. Once inside, UCA employs a layered approach that includes persistence via registry run key or Startup Folder entries, sandbox evasion through time‑based checks, obfuscated configuration decoding, and masquerading as legitimate system processes such as svchost.exe. A distinguishing characteristic of UCA is its sabotage of rival ransomware infrastructures. A recent high‑profile operation saw the group target the Trigona ransomware chain by exploiting Confluence and wiping Trigona’s operational footprint, effectively halting its activity. The actor also engages traditional ransomware tactics: file, directory and network share discovery; data encryption using the TDCP_rijndael library; optional data destruction via file truncation; and system shutdown or reboot commands that further cripple victim environments. Operationally, UCA directs attacks toward entities spanning finance, government, education, telecommunications, manufacturing, defense, healthcare, critical infrastructure, retail, media, energy, hospitality, non‑profits, and think‑tanks in countries including Ukraine, Russia, the United States, Turkey, Brazil, Germany, Great Britain and Poland. While primarily motivated by financial gain through ransom payments (including Monero transactions via TOR payment portals), their actions are heavily infused with hacktivist intent, aiming to undermine adversarial capabilities during geopolitical conflicts.

Goals & Targeting

Targeted Sectors

Financial services
Government
Education
Telecommunications
Manufacturing
Defense
Healthcare
Critical infrastructure
Retail
Media
Energy
Hospitality
Non profit
Think tank

Targeted Countries / Regions

UA
RU
US
TR
BR
DE
GB
PL

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

Ukrainian Cyber Alliance (UCA) is a hacktivist actor that leverages zero‑day vulnerabilities to penetrate, sabotage and disrupt adversarial cyber operations and infrastructure, particularly those associated with Russian interests. In addition, UCA exerts financial pressure through ransomware campaigns that target critical sectors across multiple countries. Their activities combine advanced exploitation techniques with destructive post‑exploitation actions such as data encryption, deletion, and system shutdowns.

Goals & Targeting

UCA’s strategic goals intertwine financial exploitation with the disruption of Russian‑affiliated cyber threats. By leveraging zero‑days and post‑exploitation sabotage, they aim to neutralize competing ransomware families such as Trigona, thereby reducing competition for ransom payments and gaining a tactical advantage over adversaries aligned with hostile states. Simultaneously, UCA targets high‑visibility institutions across multiple sectors to propagate political messages, assert cyber dominance in the region, and demonstrate the tangible impact of Ukraine’s cybersecurity posture on global actors.

Enhanced Description

Key Capabilities

  • Exploits zero‑day vulnerabilities such as Confluence CVE-2023-22515 and Zoho ManageEngine CVE-2021-40539
  • Implements persistence via registry run keys/Startup Folder autostart
  • Obfuscates and decrypts configuration files to bypass security controls
  • Masquerades as legitimate processes, e.g., svchost.exe
  • Employs sandbox evasion through time‑based sleep checks
  • Conducts comprehensive discovery: system owner/user info, file/directory listings, network share enumeration (NetShareEnum)
  • Executes shutdown/reboot commands to disrupt services
  • Encrypts data with TDCP_rijndael encryption library and optionally truncates files for corruption

MITRE ATT&CK Tactics

Initial Access
Discovery
Privilege Escalation
Persistence
Defense Evasion
Impact

ATT&CK Techniques

T1190
T1046
T1547.001
T1140
T1218.005
T1036.005
T1497.003
T1083
T1135
T1033
T1529
T1486
T1485

Software / Tooling

BlackEnergy
WhisperGat
Trigona
Mshta
TDCP_rijndael
NetShareEnum
BlackCat
AlphaVM

Campaigns & Victims

UCA has demonstrated a pattern of rapid, high‑impact campaigns that exploit publicly known zero‑days shortly after disclosure to compromise target systems. Victims are typically mid‑to‑large organizations involved in critical sectors across Western and Eurasian nations, including the energy, defense, and financial industries. Notable operations include the sabotage of Trigona ransomware infrastructure via a Confluence vulnerability, and the crippling ransomware attack on Donbas Post through ManageEngine exploitation, which disabled a major Ukrainian media outlet’s network, services, and call center. The actor’s tactical mix—combining stealthy exploitation, aggressive sabotage, and traditional ransomware payloads—suggests an operational tempo driven by both geopolitical objectives and monetary returns.

IOC Patterns

  • Domain
  • File
  • HTA ransom note format
  • TOR‑based payment portal
  • Monero (XMR) cryptocurrency payments
  • Zero‑day exploitation of Confluence
  • Exploitation of CVE‑2021‑40539 ManageEngine Vulnerability
  • Registry Run Keys/Startup Folder modifications for autostart
  • Decrypting configuration in 'cfgs' resource section
  • Masquerading as svchost.exe
  • MSHTA usage to display ransom note
  • Time-based sleep via /sleep argument
  • NetShareEnum network share enumeration
  • TDCP_rijndael encryption algorithm
  • Shutdown/reboot commands (/shdwn)
  • File truncation for data destruction (/erase)

Recommended Actions

  • Patch critical applications immediately—especially Confluence (CVE‑2023-22515) and Zoho ManageEngine ADSelfService Plus (CVE‑2021‑40539)—and maintain an up‑to‑date vulnerability management program.
  • Deploy intrusion detection and prevention systems that specifically monitor traffic to vulnerable services such as ManageEngine and Confluence, with alerts for exploitation attempts.
  • Implement endpoint security monitoring for .HTA files, masqueraded binaries like svchost.exe, and the execution of MSHTA or PowerShell scripts suspected of delivering ransom notes.
  • Enforce strict change‑control policies to detect unauthorized registry run key/Startup Folder modifications; use configuration baselines and file integrity monitoring. "Detect sandbox evasion by monitoring for time‑based sleep patterns (/sleep) and unusual process trees that spawn mshta.exe or other scripting hosts." Monitor outbound TOR traffic and suspicious cryptocurrency wallet activity (Monero); block or audit such connections where feasible.
  • Maintain rigorous network share access controls and monitor for broad NetShareEnum enumerations; segment shares to limit ransom spread. Ensure frequent, verified backups are stored offline and tested regularly to facilitate rapid recovery from data encryption or deletion events." "Develop incident‑response playbooks that address sabotage incidents, including protocols for handling systemic shutdown/reboot commands and verifying the integrity of post‑exploitation cleanup actions."

Suggested Tags

cyber‑warfare
hacktivism
zero‑day exploit
ransomware sabotage
Ukrainian Cyber Alliance
UCA
Trigona
BlackCat
AlphaVM
CVE-2021-40539
TDCP_rijndael
network share enumeration
sandbox evasion
MSHTA
masquerading
data encryption
data destruction
ransom note

Confidence Assessment

The analysis is grounded in multiple independent sources that corroborate UCA’s use of zero‑day exploits, sabotage tactics, and ransomware activities. Confidence is moderate to high regarding the group’s capabilities, known operations, and target profiles. Gaps remain around precise operational dates, full attribution evidence linking all observed behaviors to a single entity, and detailed financial profiling (e.g., ransomware payment volumes). Future intelligence collection should focus on confirming timeline continuity and expanding visibility into UCA's internal command‑and‑control infrastructure.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. unit42.paloaltonetworks.com — Cited by web research for: BlackCat
  2. www.trendmicro.com — Cited by web research for: AlphaVM
  3. brandefense.io — Cited by web research for: Cozy Bear
  4. www.sentinelone.com — Cited by web research for: BlackCat
  5. research.checkpoint.com — Cited by web research for: Crisis

Intel Summary

13

Techniques

46

Tools

0

Campaigns

37

IOCs

0

Observed Data

5

Tactics

Tags

Data Exfiltration
Hacktivism
Cyber Espionage
Critical Infrastructure
Energy Sector
Government Targeting
cyber‑warfare
hacktivism
zero‑day exploit
ransomware sabotage
Ukrainian Cyber Alliance
UCA
Trigona
BlackCat
AlphaVM
CVE-2021-40539
TDCP_rijndael
network share enumeration
sandbox evasion
MSHTA
masquerading
data encryption
data destruction
ransom note

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
U
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.