Also known as: tracked as, techniki, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Travnet, Mustang Panda, procedury
UAC‑0245, also identified by a variety of aliases including APT39, Chafer, Remexi and Mustang Panda, has been active since at least the early 2010s. Its operations span a wide geographic footprint—targeting entities in Ukraine, the United States, Iran, Mexico, India, Vietnam, North Korea, South Korea, Belarus, Azerbaijan and China—and include sectors ranging from government and defense to finance, energy, media and manufacturing. A key element of its toolkit is the CABINETRAT backdoor, leveraged for command‑and‑control within compromised Windows environments and delivered via malicious XLL add‑ins or ZIP attachments. The actor also exploits critical software vulnerabilities (e.g., CVE‑2025‑61882 in Oracle E‑Business Suite) to gain remote code execution; after establishing footholds it frequently deploys ransomware‑as‑a‑service offerings such as CL0P to extort victims. Tactics are diverse: UAC‑0245 manipulates access tokens through creation, impersonation, SID‑history injection and parent PID spoofing, enabling stealthy escalation and lateral spread. The group routinely encodes exfiltrated data using Base64, Hex or MIME; it abuses external remote services for movement, probes backup software and network shares, and abuses container CLI/APIs to pivot within cloud or on‑premises Kubernetes environments. Proxy execution via MSBuild, ClickOnce and JamPlus further obfuscates its activity. Additionally, UAC‑0245 has demonstrated capabilities in denial‑of‑service attacks (both classic DDoS and network‑level DoS), audio/video capture for espionage purposes, and suppression of system recovery functions. The combination of legacy APT techniques with modern container and cloud abuse tools places the actor among the most adaptable threat groups targeting critical infrastructure.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0245 is a financially motivated threat actor that has conducted DDoS, exploitation of critical software and ransomware campaigns across multiple countries and sectors, including recent operations in Ukraine using the CABINETRAT backdoor. The group blends traditional APT techniques such as token manipulation and inter‑process communication with newer container‑based abuse to achieve persistence and lateral movement. Organizations should prioritize patching known vulnerabilities, monitoring for encoded traffic and unusual process creation, and hardening their remote service access.
Goals & Targeting
The primary strategic objective of UAC‑0245 appears to be financial gain achieved through extortion (via ransomware) and potentially data theft for monetization. By targeting government, defense, and critical infrastructure sectors it seeks high‑value information or leverage; the use of DDoS attacks further serves to disrupt operations and compel payment demands. The actor’s geographic focus on Ukraine reflects a strategic adversarial stance, whereas its broader global reach indicates opportunistic exploitation of vulnerable assets worldwide.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0245’s historical activity includes early 2010s DDoS operations against U.S. infrastructure and later high‑profile attacks in Ukraine, deploying CABINETRAT via malicious Office attachments or ZIP payloads that leverage XLL add‑ins. The group demonstrates a rapid operational tempo, switching from pure disruption (DDoS) to financially motivated ransomware campaigns when opportunities arise. Victims span public sector entities—particularly those in defense and critical infrastructure—and private organizations with large media, energy, or financial footprints. Recent campaigns also exhibit complex lateral movement across heterogeneous environments, including Windows, Linux, macOS, and containerized platforms. Notable past operations link UAC‑0245 to Mustang Panda and Chafer campaigns targeting Iranian diplomatic staff, evidencing a persistent focus on political influence alongside monetary extortion. The actor’s blend of legacy persistence methods (MSBuild/ClickOnce/JamPlus) with cutting‑edge container abuse positions it as an advanced threat capable of adapting to security posture changes rapidly.
IOC Patterns
Recommended Actions
Confidence Assessment
The confidence in the core tactics, techniques, and motivations of UAC‑0245 is moderate to high, based on multiple independent reports and observed campaign artifacts. However, gaps remain regarding the full extent of its toolset (particularly newer container‑based utilities), precise attribution timelines, and whether all listed aliases map to a single unified group or are overlapping sub‑units. Continued monitoring of IOC signatures and emerging threat intelligence updates will help refine this assessment.
No campaigns linked yet.
No observed data linked yet.
49
Techniques
42
Tools
0
Campaigns
40
IOCs
0
Observed Data
14
Tactics