Also known as: TAG-160, TAG-161, RefBroker, Fancy Bear, APT28, TAG-150, impersonates Booking.com, Matanbuchus, tracked as, Fighting Ursa, the Immigration, congregate care, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, Bleeding Bear by CrowdStrike, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Gamaredon APT, REvil, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, Qakbot
UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various organizations in the European Union. The group employs phishing campaigns that utilize SVG file attachments to distribute stealers like Amatera Stealer and Strela Stealer. Their tactics include leveraging ClickFix-style methods to implement their threats.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC-0227 is a recently identified advanced persistent threat (APT) group active since March 2025, targeting local governments, critical infrastructure, and organizations across the European Union. The group employs sophisticated phishing campaigns using SVG file attachments to deploy stealers like Amatera Stealer and Strela Stealer. Their operations demonstrate moderate technical capability and focus on data collection and potential disruption of targeted sectors.
Goals & Targeting
UAC-0227 targets local governments, critical infrastructure, and various organizations within the European Union, suggesting a strategic focus on sectors that hold sensitive information or could be critical for public welfare. The group's choice of tools like Amatera Stealer suggests an intent to collect sensitive data, potentially for espionage or financial gain. The targeting of critical infrastructure may indicate a desire to disrupt services or gain influence over key societal components.
Enhanced Description
UAC-0227 is an APT group that has emerged as a threat in March 2025, with its activities observed primarily within the European Union. The group's primary method of attack involves phishing campaigns utilizing SVG file attachments, which serve as a vector for distributing malicious software such as Amatera Stealer and Strela Stealer. These tools are designed to steal sensitive information from infected systems. UAC-0227 has also been observed using ClickFix-style methods to implement their threats, indicating a preference for specific attack vectors and techniques. While the group's operational history is still limited, its targeting of critical infrastructure and local governments suggests an intent to disrupt or gather intelligence that could impact national security or public services. The group's use of relatively new and less commonly known tools indicates moderate sophistication in their tactics and tools. Despite this, UAC-0227 appears to have a focused strategy, aiming to compromise specific types of data and systems.
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC-0227 has demonstrated a consistent focus on European targets, suggesting potential regional or specific-intelligence interests. Their campaigns are characterized by the use of SVG-based phishing and ClickFix methods for threat deployment. While specific campaign details are limited, the group’s activities indicate a modus operandi that combines targeted phishing with data theft tools to compromise high-value assets. Notable past operations include multiple waves of phishing attacks against critical infrastructure entities.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Confidence in UAC-0227's activities is moderate given its recent emergence and limited observable history. While the group has demonstrated persistent targeting patterns, data gaps include specific geographic or sectoral preferences beyond Europe. Additionally, the long-term objectives of the group remain speculative.
No campaigns linked yet.
No observed data linked yet.
29
Techniques
41
Tools
0
Campaigns
40
IOCs
0
Observed Data
10
Tactics