Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0227

Also known as: TAG-160, TAG-161, RefBroker, Fancy Bear, APT28, TAG-150, impersonates Booking.com, Matanbuchus, tracked as, Fighting Ursa, the Immigration, congregate care, Head Mare, 21, 2026, Kyrgyzstan, Kazakhstan, defense industries, Awaken Likho, Bearlyfy, Librarian Ghouls, Librarian Likho, Rezet, Core Werewolf, Lone Wolf, Moonshine Trickster, Ratopak Spider, UAC-0008, Romania, UAC-0001, its NATO allies, Outrider Tiger, Fishing Elephant, Earth Vetala, MERCURY, Mango Sandstorm, Static Kitten, including diplomatic, maritime, financial, Bleeding Bear by CrowdStrike, Bloody Wolf, SkyCloak, laboo.boo, Clubfoot Wolf, Void Arachne, Watch Wolf, Forest Blizzard, TA450, Archer RAT, RUSTRIC, detects installed security software, establishes contact with a, MuddyWater, CHAR, Olalampo, Storm-0842, Red Sandstorm, Banished Kitten, HOPPINGANT by researchers, Yorotrooper, Tomiris, Advanced Persistent Threat 39, Chafer, Cadelspy, Remexi, ITG07, Gamaredon APT, REvil, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, Qakbot

Description

UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various organizations in the European Union. The group employs phishing campaigns that utilize SVG file attachments to distribute stealers like Amatera Stealer and Strela Stealer. Their tactics include leveraging ClickFix-style methods to implement their threats.

Goals & Targeting

Targeted Sectors

Government
Financial services
Transportation
Defense
Energy
Manufacturing
Telecommunications
Education
Critical infrastructure
Maritime
Construction
Healthcare
Media
Non profit
Aerospace
Retail
Utilities
Aviation
Chemical
Nuclear
Mining
Hospitality
Information technology

Targeted Countries / Regions

US
RU
UA
CN
AE
KP
PL
PK
TW
KZ
BR
IL
SA
KR
TR
BY
RO
GB
MX
ES
IN
NL
VN
JP
SG
NG
IT
DE
AZ
AU
IR

AI Analysis

· 1 week ago

Executive Summary

UAC-0227 is a recently identified advanced persistent threat (APT) group active since March 2025, targeting local governments, critical infrastructure, and organizations across the European Union. The group employs sophisticated phishing campaigns using SVG file attachments to deploy stealers like Amatera Stealer and Strela Stealer. Their operations demonstrate moderate technical capability and focus on data collection and potential disruption of targeted sectors.

Goals & Targeting

UAC-0227 targets local governments, critical infrastructure, and various organizations within the European Union, suggesting a strategic focus on sectors that hold sensitive information or could be critical for public welfare. The group's choice of tools like Amatera Stealer suggests an intent to collect sensitive data, potentially for espionage or financial gain. The targeting of critical infrastructure may indicate a desire to disrupt services or gain influence over key societal components.

Enhanced Description

UAC-0227 is an APT group that has emerged as a threat in March 2025, with its activities observed primarily within the European Union. The group's primary method of attack involves phishing campaigns utilizing SVG file attachments, which serve as a vector for distributing malicious software such as Amatera Stealer and Strela Stealer. These tools are designed to steal sensitive information from infected systems. UAC-0227 has also been observed using ClickFix-style methods to implement their threats, indicating a preference for specific attack vectors and techniques. While the group's operational history is still limited, its targeting of critical infrastructure and local governments suggests an intent to disrupt or gather intelligence that could impact national security or public services. The group's use of relatively new and less commonly known tools indicates moderate sophistication in their tactics and tools. Despite this, UAC-0227 appears to have a focused strategy, aiming to compromise specific types of data and systems.

Key Capabilities

  • Phishing campaigns utilizing SVG file attachments
  • Deployment of Amatera Stealer and Strela Stealer for data theft
  • Use of ClickFix-style methods for threat implementation
  • Command-and-control (C2) communication via HTTP/S protocols
  • Network persistence through scheduled task creation
  • Encrypted exfiltration channels for stolen data
  • Lateral movement within compromised networks

MITRE ATT&CK Tactics

Initial Access
Credential Access
Collection
Exfiltration and Transfer
Impact

ATT&CK Techniques

T1566.001
T1078
T1055
T1042
T1091
T1568
T1567

Software / Tooling

Amatera Stealer
Strela Stealer
ClickFix-style tools
Custom C2 Framework

Campaigns & Victims

UAC-0227 has demonstrated a consistent focus on European targets, suggesting potential regional or specific-intelligence interests. Their campaigns are characterized by the use of SVG-based phishing and ClickFix methods for threat deployment. While specific campaign details are limited, the group’s activities indicate a modus operandi that combines targeted phishing with data theft tools to compromise high-value assets. Notable past operations include multiple waves of phishing attacks against critical infrastructure entities.

IOC Patterns

  • Spear-phishing emails containing malicious SVG files
  • Malicious domains used for C2 communication mimicking legitimate services
  • Network traffic anomalies from scheduled task persistence mechanisms
  • Presence of encrypted data exfiltration channels

Recommended Actions

  • Implement employee training on identifying and reporting suspicious phishing emails
  • Monitor network traffic for known TTPs associated with UAC-0227, such as SVG-based phishing
  • Conduct regular vulnerability scans and penetration testing to identify potential attack vectors
  • Use endpoint detection and response (EDR) solutions to detect malicious activity like Amatera Stealer or Strela Stealer
  • Adopt multi-factor authentication (MFA) for critical systems to mitigate credential theft
  • Review and enhance incident response plans to address potential APT-like intrusions

Suggested Tags

APT
Espionage
Critical Infrastructure
European Union
Phishing
Stealers

Confidence Assessment

Confidence in UAC-0227's activities is moderate given its recent emergence and limited observable history. While the group has demonstrated persistent targeting patterns, data gaps include specific geographic or sectoral preferences beyond Europe. Additionally, the long-term objectives of the group remain speculative.

ATT&CK Techniques

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

IPv4 Address 8 Domain 11 Filename 1

References

  1. www.recordedfuture.com — Cited by web research for: TAG-160
  2. ics-cert.kaspersky.com — Cited by web research for: APT28
  3. attack.mitre.org — Cited by web research for: T1071.002
  4. ics-cert.kaspersky.com — Cited by web research for: FatalRat
  5. www.proofpoint.com — Cited by web research for: Trixauvex

Intel Summary

29

Techniques

41

Tools

0

Campaigns

40

IOCs

0

Observed Data

10

Tactics

Tags

APT
Critical Infrastructure
Phishing
Government Targeting
Espionage
European Union
Stealers

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
Iran (IR)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.