Also known as: tracked as, using phishing lures, screenshots from compromised computers
UAC‑0219 has emerged as an active threat actor focused on gathering sensitive information from Ukrainian critical sectors, including government agencies, transportation networks, and defense-related organizations. The group’s primary toolset centers around the custom WRECKSTEEL malware family, delivered via phishing lures that mimic legitimate human resources or governmental correspondence. In addition to the VBScript and PowerShell variants of WRECKSTEEL, adversaries have incorporated classic delivery vectors such as zip archives sent over email, WeChat, or Telegram. Operationally, the campaigns begin with spearphishing attachments containing macro‑enabled Office files that trigger a downloader script hosted on publicly accessible platforms. Once executed, the backdoor establishes persistence through Windows scheduled tasks and process injection while exfiltrating captured data—including screenshots, audio recordings, and system credentials—over encrypted channels utilizing HTTP or DNS tunneling. The attackers also employ system discovery techniques to map and enumerate target environments. Multiple advisories from CERT‑UA (alert #14283) and Kaspersky’s incident reports confirm the attribution of these attacks to a Russian intelligence organization—believed to be linked with GRU or related factions—and highlight ongoing efforts to expand beyond Ukraine into other parts of Eastern Europe and the Asia‑Pacific region. Given the strategic nature of the information exfiltrated, UAC‑0219 is regarded as a high‑impact espionage actor with potential implications for national security. The group continues to refine its tactics, leveraging emerging AI-driven social engineering cues to bypass traditional email defenses while maintaining low visibility within victim environments. Their campaigns exhibit an operational tempo that can shift from slow, incremental data harvests to rapid, targeted strikes on high‑priority systems.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0219 is a Russian state‑sponsored cyber espionage group that has been targeting Ukrainian critical infrastructure and government entities since early 2024. The group employs sophisticated spearphishing campaigns, delivering custom VBScript and PowerShell implants that steal data through the WRECKSTEEL stealer. Their operations consistently exhibit stealthy persistence, encrypted exfiltration, and a focus on obtaining strategic intelligence from transportation, defense, and public sector targets.
Goals & Targeting
UAC‑0219’s strategic objectives revolve around the acquisition of actionable intelligence that benefits a state–level adversary. By infiltrating Ukrainian transportation, defense, and infrastructure sectors, the actor seeks to monitor technological advancements, military logistics, and civil agency operations. The focus on specific countries—Ukraine and other Eastern European states, as well as select Asian‑Pacific economies—suggests a geopolitical agenda aimed at weakening regional security postures and gathering data that can inform future operational planning or political leverage. Typical victims include public institutions such as local governments, federal ministries, law‑enforcement agencies, railway operators, power plants, and healthcare facilities. The actor’s choice of targets reflects an interest in both strategic assets (e.g., energy grids) and high‑volume data sources that can supply continuous intelligence streams.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0219 regularly launches multi‑stage campaigns that begin with mass phishing of government or corporate employees, followed by staged payload deployment. The attacks exhibit a consistent pattern of slow data harvesting combined with rapid lateral movement across Windows domains. Victims are typically large public or semi‑public entities where administrative privileges can be readily leveraged. Notably, CERT‑UA alerts indicate a surge in activity targeting energy and transport sectors, while Kaspersky reports suggest spill‑over into Asian‑Pacific industrial targets. The actor’s operational tempo is flexible—allowing for both low‑profile, long‑term espionage missions and swift data exfiltration when strategic urgency arises. One key distinguishing feature is the use of a custom stealer, WRECKSTEEL, that incorporates advanced encryption and modular architecture, enabling the attacker to pivot quickly between different data sources. The group also demonstrates an ability to adapt its delivery methods (email, WeChat, Telegram) to bypass traditional security filters. Overall, UAC‑0219’s operations illustrate a textbook state‑sponsored APT campaign, focused on geopolitical intelligence gathering rather than financial gain or destructive sabotage.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The attribution of UAC‑0219 to a state‑sponsored actor, particularly with ties to Russian intelligence, is substantiated by multiple independent advisories from CERT‑UA and Kaspersky, providing strong confidence in the strategic intent and target selection. Technical details regarding WRECKSTEEL’s deployment via phishing lures, use of VBScript/PowerShell, and data exfiltration techniques are well documented, which supports high confidence in those assertions. Areas of uncertainty include the precise timelines for initial deployment, detailed infrastructure (C2 domains, VPS hosts), and full toolset breadth beyond WRECKSTEEL. Some reported tools such as FatalRAT or ROKRAT appear in broader threat landscapes but direct attribution to UAC‑0219 remains less clear. Consequently, confidence is moderate regarding the exact extent of the actor’s operational capabilities. Information gaps persist around the long‑term persistence mechanisms post‑infection, frequency of lateral movement across national networks, and any potential collaboration with other adversary groups.
No campaigns linked yet.
No observed data linked yet.
43
Techniques
48
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics