Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0245

Also known as: tracked as, techniki, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Travnet, Mustang Panda, procedury

Description

UAC‑0245, also identified by a variety of aliases including APT39, Chafer, Remexi and Mustang Panda, has been active since at least the early 2010s. Its operations span a wide geographic footprint—targeting entities in Ukraine, the United States, Iran, Mexico, India, Vietnam, North Korea, South Korea, Belarus, Azerbaijan and China—and include sectors ranging from government and defense to finance, energy, media and manufacturing. A key element of its toolkit is the CABINETRAT backdoor, leveraged for command‑and‑control within compromised Windows environments and delivered via malicious XLL add‑ins or ZIP attachments. The actor also exploits critical software vulnerabilities (e.g., CVE‑2025‑61882 in Oracle E‑Business Suite) to gain remote code execution; after establishing footholds it frequently deploys ransomware‑as‑a‑service offerings such as CL0P to extort victims. Tactics are diverse: UAC‑0245 manipulates access tokens through creation, impersonation, SID‑history injection and parent PID spoofing, enabling stealthy escalation and lateral spread. The group routinely encodes exfiltrated data using Base64, Hex or MIME; it abuses external remote services for movement, probes backup software and network shares, and abuses container CLI/APIs to pivot within cloud or on‑premises Kubernetes environments. Proxy execution via MSBuild, ClickOnce and JamPlus further obfuscates its activity. Additionally, UAC‑0245 has demonstrated capabilities in denial‑of‑service attacks (both classic DDoS and network‑level DoS), audio/video capture for espionage purposes, and suppression of system recovery functions. The combination of legacy APT techniques with modern container and cloud abuse tools places the actor among the most adaptable threat groups targeting critical infrastructure.

Goals & Targeting

Targeted Sectors

Government
Defense
Non profit
Financial services
Media
Maritime
Energy
Nuclear
Manufacturing
Oil gas
Education
Mining
Telecommunications
Think tank

Targeted Countries / Regions

UA
US
IR
MX
IN
VN
KP
KR
BY
AZ
CN

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 1 day ago

Executive Summary

UAC‑0245 is a financially motivated threat actor that has conducted DDoS, exploitation of critical software and ransomware campaigns across multiple countries and sectors, including recent operations in Ukraine using the CABINETRAT backdoor. The group blends traditional APT techniques such as token manipulation and inter‑process communication with newer container‑based abuse to achieve persistence and lateral movement. Organizations should prioritize patching known vulnerabilities, monitoring for encoded traffic and unusual process creation, and hardening their remote service access.

Goals & Targeting

The primary strategic objective of UAC‑0245 appears to be financial gain achieved through extortion (via ransomware) and potentially data theft for monetization. By targeting government, defense, and critical infrastructure sectors it seeks high‑value information or leverage; the use of DDoS attacks further serves to disrupt operations and compel payment demands. The actor’s geographic focus on Ukraine reflects a strategic adversarial stance, whereas its broader global reach indicates opportunistic exploitation of vulnerable assets worldwide.

Enhanced Description

Key Capabilities

  • Denial‑of‑Service (DDoS) attacks
  • Deployment of CABINETRAT backdoor for command and control
  • Exploitation of Oracle E‑Business Suite CVE‑2025‑61882 for remote code execution
  • Use of ransomware‑as‑a‑service CL0P for extortion
  • Access token manipulation (creation, impersonation, SID‑history injection, parent PID spoofing)
  • Data encoding/obfuscation using Base64, Hex and MIME
  • External remote service exploitation for lateral movement
  • Automatic discovery of backup software and network share resources
  • Abuse of container CLI/API via Docker/Kubernetes
  • Proxy execution with MSBuild, ClickOnce and JamPlus
  • Video and audio capture capabilities

MITRE ATT&CK Tactics

Initial Access
Command and Control
Impact
Credential Access
Privilege Escalation
Discovery
Lateral Movement
Defense Evasion
Collection

ATT&CK Techniques

T1056.001
T1056.002
T1056.003
T1056.004
T1059.013
T1102
T1112
T1124
T1125
T1127.001
T1127.002
T1127.003
T1128
T1129
T1132.001
T1132.002
T1133
T1134.001
T1134.002
T1134.003
T1134.004
T1134.005
T1158
T1190
T1505
T1518.002
T1550
T1550.001
T1558.004
T1559.001
T1559.002
T1559.003
T1560.001
T1560.002
T1560.003
T1571
T1584

Software / Tooling

CABINETRAT
CL0P
Remexi
NETWIRE
BOOKWORM
Crimson
Machete
BlackEnergy
ROKRAT
PlugX
Remsec
DarkGate
Carbanak
LODEINFO
KONNI
CorKLOG
MacMa
njRAT
Agent Tesla
PAKLOG
InvisibleFerret
Cobalt Strike

Campaigns & Victims

UAC‑0245’s historical activity includes early 2010s DDoS operations against U.S. infrastructure and later high‑profile attacks in Ukraine, deploying CABINETRAT via malicious Office attachments or ZIP payloads that leverage XLL add‑ins. The group demonstrates a rapid operational tempo, switching from pure disruption (DDoS) to financially motivated ransomware campaigns when opportunities arise. Victims span public sector entities—particularly those in defense and critical infrastructure—and private organizations with large media, energy, or financial footprints. Recent campaigns also exhibit complex lateral movement across heterogeneous environments, including Windows, Linux, macOS, and containerized platforms. Notable past operations link UAC‑0245 to Mustang Panda and Chafer campaigns targeting Iranian diplomatic staff, evidencing a persistent focus on political influence alongside monetary extortion. The actor’s blend of legacy persistence methods (MSBuild/ClickOnce/JamPlus) with cutting‑edge container abuse positions it as an advanced threat capable of adapting to security posture changes rapidly.

IOC Patterns

  • CVE-2025-61882 exploitation
  • Remote code execution indicators
  • CABINETRAT backdoor binaries and registry keys
  • CL0P ransomware dropper signatures
  • Base64/Hex/MIME encoded data patterns
  • Alternate token process creation
  • External remote service usage ","Container CLI/API abuse patterns","XLL add‑in malicious behavior","ZIP file attachment delivery mechanisms

Recommended Actions

  • Patch Oracle E‑Business Suite to mitigate CVE‑2025‑61882 prior to exploitation deadlines.
  • Deploy IDS/IPS and Sigma rules targeting CABINETRAT command‑and‑control traffic.
  • Implement DDoS mitigation (scrubbing, rate limiting) for critical endpoints.
  • Monitor network for encoded data flows using Base64/MIME and flag anomalous process creation with alternate tokens.
  • Enforce least privilege; audit and restrict container CLI/API usage.
  • Block or sandbox MSBuild, ClickOnce, JamPlus execution, unless explicitly authorized.
  • Detect and quarantine suspicious XLL add‑in files in Office documents.
  • Disable deprecated Kerberos abuse vectors such as AS‑REP roasting through AD policy restrictions.
  • Restrict outbound external remote services; whitelist necessary ports and implement strict access monitoring. "],

Confidence Assessment

The confidence in the core tactics, techniques, and motivations of UAC‑0245 is moderate to high, based on multiple independent reports and observed campaign artifacts. However, gaps remain regarding the full extent of its toolset (particularly newer container‑based utilities), precise attribution timelines, and whether all listed aliases map to a single unified group or are overlapping sub‑units. Continued monitoring of IOC signatures and emerging threat intelligence updates will help refine this assessment.

ATT&CK Techniques

Credential Access
1 technique
Defense impairment
1 technique
Resource Development
1 technique

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. cert.orange.pl — Cited by web research for: techniki
  2. attack.mitre.org — Cited by web research for: Advanced Persistent Threat 39
  3. attack.mitre.org — Cited by web research for: T1518.002
  4. https://daily.dev/posts/ukraine-warns-of-cabinetrat-backdoor-xll-add-ins-spread-via-signal-zips-a653rsbic — Cited by AI analysis.

Intel Summary

49

Techniques

42

Tools

0

Campaigns

40

IOCs

0

Observed Data

14

Tactics

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.