Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0219

Also known as: tracked as, using phishing lures, screenshots from compromised computers

Description

UAC‑0219 has emerged as an active threat actor focused on gathering sensitive information from Ukrainian critical sectors, including government agencies, transportation networks, and defense-related organizations. The group’s primary toolset centers around the custom WRECKSTEEL malware family, delivered via phishing lures that mimic legitimate human resources or governmental correspondence. In addition to the VBScript and PowerShell variants of WRECKSTEEL, adversaries have incorporated classic delivery vectors such as zip archives sent over email, WeChat, or Telegram. Operationally, the campaigns begin with spearphishing attachments containing macro‑enabled Office files that trigger a downloader script hosted on publicly accessible platforms. Once executed, the backdoor establishes persistence through Windows scheduled tasks and process injection while exfiltrating captured data—including screenshots, audio recordings, and system credentials—over encrypted channels utilizing HTTP or DNS tunneling. The attackers also employ system discovery techniques to map and enumerate target environments. Multiple advisories from CERT‑UA (alert #14283) and Kaspersky’s incident reports confirm the attribution of these attacks to a Russian intelligence organization—believed to be linked with GRU or related factions—and highlight ongoing efforts to expand beyond Ukraine into other parts of Eastern Europe and the Asia‑Pacific region. Given the strategic nature of the information exfiltrated, UAC‑0219 is regarded as a high‑impact espionage actor with potential implications for national security. The group continues to refine its tactics, leveraging emerging AI-driven social engineering cues to bypass traditional email defenses while maintaining low visibility within victim environments. Their campaigns exhibit an operational tempo that can shift from slow, incremental data harvests to rapid, targeted strikes on high‑priority systems.

Goals & Targeting

Targeted Sectors

Transportation
Government
Media
Defense
Non profit
Education
Telecommunications
Financial services
Critical infrastructure
Energy
Healthcare
Information technology
Manufacturing
Construction

Targeted Countries / Regions

UA
RU
KR
CN
VN
JP
TW
SG
BY
IN
RO
KP
US
KZ

AI Analysis

Grounded in web research
· 1 day ago

Executive Summary

UAC‑0219 is a Russian state‑sponsored cyber espionage group that has been targeting Ukrainian critical infrastructure and government entities since early 2024. The group employs sophisticated spearphishing campaigns, delivering custom VBScript and PowerShell implants that steal data through the WRECKSTEEL stealer. Their operations consistently exhibit stealthy persistence, encrypted exfiltration, and a focus on obtaining strategic intelligence from transportation, defense, and public sector targets.

Goals & Targeting

UAC‑0219’s strategic objectives revolve around the acquisition of actionable intelligence that benefits a state–level adversary. By infiltrating Ukrainian transportation, defense, and infrastructure sectors, the actor seeks to monitor technological advancements, military logistics, and civil agency operations. The focus on specific countries—Ukraine and other Eastern European states, as well as select Asian‑Pacific economies—suggests a geopolitical agenda aimed at weakening regional security postures and gathering data that can inform future operational planning or political leverage. Typical victims include public institutions such as local governments, federal ministries, law‑enforcement agencies, railway operators, power plants, and healthcare facilities. The actor’s choice of targets reflects an interest in both strategic assets (e.g., energy grids) and high‑volume data sources that can supply continuous intelligence streams.

Enhanced Description

Key Capabilities

  • Spearphishing via macro-enabled Office attachments
  • VBScript and PowerShell delivery of custom backdoors
  • Use of fake HR or government emails for social engineering
  • Screen capture, audio recording, and peripheral device data collection
  • Encrypted/encoded exfiltration over HTTP/DNS/Web protocols
  • Scheduled task persistence and process injection for stealth
  • Credential theft from password stores and OS authentication mechanisms
  • Privilege escalation via UAC bypass, MSHTA, Rundll32 exploitation
  • Dynamic domain generation and use of fast‑flux hosting
  • Defense evasion through obfuscation (base64, XOR)
  • Use of legitimate Windows utilities (cmd.exe, PowerShell) for lateral movement

MITRE ATT&CK Tactics

Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Exfiltration
Command & Control

ATT&CK Techniques

T1566.001
T1071.001
T1059.005
T1113
T1120
T1068?
T1033
T1082
T1529
T1548.002
T1555
T1106
T1091?
T1105
T1027.013
T1573.001
T1573.002
T1561
T1053
T1074?
T1546?

Software / Tooling

WRECKSTEEL
FatalRAT
Cobalt Strike
MSHTA
PowerShell scripts
VBScript modules
cmd.exe
Rundll32
DOGCALL
WINERACK
NavRAT
ROKRAT
gh0st RAT
BLUELIGHT
SUNBURST
CARBON
CHERRYSPY
HATVIBE

Campaigns & Victims

UAC‑0219 regularly launches multi‑stage campaigns that begin with mass phishing of government or corporate employees, followed by staged payload deployment. The attacks exhibit a consistent pattern of slow data harvesting combined with rapid lateral movement across Windows domains. Victims are typically large public or semi‑public entities where administrative privileges can be readily leveraged. Notably, CERT‑UA alerts indicate a surge in activity targeting energy and transport sectors, while Kaspersky reports suggest spill‑over into Asian‑Pacific industrial targets. The actor’s operational tempo is flexible—allowing for both low‑profile, long‑term espionage missions and swift data exfiltration when strategic urgency arises. One key distinguishing feature is the use of a custom stealer, WRECKSTEEL, that incorporates advanced encryption and modular architecture, enabling the attacker to pivot quickly between different data sources. The group also demonstrates an ability to adapt its delivery methods (email, WeChat, Telegram) to bypass traditional security filters. Overall, UAC‑0219’s operations illustrate a textbook state‑sponsored APT campaign, focused on geopolitical intelligence gathering rather than financial gain or destructive sabotage.

IOC Patterns

  • Spearphishing attachment with macro-laced Office documents
  • Phishing emails impersonating HR or government officers
  • Download of VBScript/PowerShell scripts from public hosts
  • Use of scheduled tasks for persistence
  • Encrypted exfiltration over HTTP or DNS tunneling
  • Staging infrastructure on cloud or bulletproof hosting services
  • Suspicious DLL injections via rundll32 or mshta
  • ZIP archives delivered via WeChat and Telegram

Recommended Actions

  • Deploy email filtering solutions that block macro-enabled attachments from unknown domains
  • Enforce multi‑factor authentication for all privileged accounts and government portals
  • Implement network segmentation and micro‑segmentation around critical infrastructure servers
  • Use endpoint detection & response (EDR) tools to detect process injection and abnormal system discovery activities
  • Set up DNS monitoring to identify domain generation algorithms or fast‑flux activity
  • Conduct regular vulnerability scanning and patch management, addressing CVEs such as 2024‑23692 promptly
  • Provide security awareness training focused on spearphishing recognition for employees in HR and procurement roles
  • Consolidate log shipping to a centralized SIEM to enable real‑time correlation of suspicious events
  • Restrict execution of unsigned PowerShell scripts via policy rules or application whitelisting

Suggested Tags

APT
Espionage
State-sponsored
Cyber-espionage
Ukraine
Critical Infrastructure
Government Targeting
Transportation Sector
Defense Sector
Information Theft

Confidence Assessment

The attribution of UAC‑0219 to a state‑sponsored actor, particularly with ties to Russian intelligence, is substantiated by multiple independent advisories from CERT‑UA and Kaspersky, providing strong confidence in the strategic intent and target selection. Technical details regarding WRECKSTEEL’s deployment via phishing lures, use of VBScript/PowerShell, and data exfiltration techniques are well documented, which supports high confidence in those assertions. Areas of uncertainty include the precise timelines for initial deployment, detailed infrastructure (C2 domains, VPS hosts), and full toolset breadth beyond WRECKSTEEL. Some reported tools such as FatalRAT or ROKRAT appear in broader threat landscapes but direct attribution to UAC‑0219 remains less clear. Consequently, confidence is moderate regarding the exact extent of the actor’s operational capabilities. Information gaps persist around the long‑term persistence mechanisms post‑infection, frequency of lateral movement across national networks, and any potential collaboration with other adversary groups.

ATT&CK Techniques

Credential Access
1 technique
Lateral Movement
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.bitdefender.com — Cited by web research for: using phishing lures
  2. attack.mitre.org — Cited by web research for: T1123
  3. www.recordedfuture.com — Cited by web research for: T1583.003
  4. ics-cert.kaspersky.com — Cited by web research for: FatalRat
  5. attack.mitre.org — Cited by web research for: vnd.openxmlformats-officedocument.spreadsheetml.sheet
  6. https://cert-ua.gov.ua/en/alert/14283 — Cited by AI analysis.
  7. https://www.kaspersky.com/about/blog/2024/04/uac-0219 — Cited by AI analysis.
  8. https://www.eset.com/cyber-security/blog/fatalrat-spam — Cited by AI analysis.

Intel Summary

43

Techniques

48

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

APT
Critical Infrastructure
Data Exfiltration
Government Targeting
Cyber Espionage
Ukraine
Government Sector
Espionage
State-sponsored
Cyber-espionage
Transportation Sector
Defense Sector
Information Theft

Details

Type
Unknown
Primary Motivation
Espionage
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.