Also known as: TAG-160, TAG-161, TAG-150, a technically sophisticated, impersonates Booking.com, Matanbuchus, APT29, tracked as, Tech Sectors, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, RefBroker, Qakbot, other threat actors, Agrius, Masked Spider
UAC-0239 has been observed conducting spearphishing attacks targeting the Defence Forces and local state agencies of Ukraine, impersonating the Security Service of Ukraine. The group employs the OrcaC2 framework and FILEMESS stealer to compromise these organizations. Their campaigns often utilize themes related to "countering russian sabotage-reconnaissance groups" to disguise their malicious intent.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0239 is a financially driven threat actor that focuses on Ukrainian state institutions and a wide range of civilian sectors by leveraging spearphishing and impersonation tactics. The group uses the OrcaC2 command‑and‑control framework together with the FILEMESS infostealer to exfiltrate data, while distributing its payloads via malicious load postings on freight‑matching platforms and sophisticated ClickFix links. Their approach includes a malware‑as‑a‑service model that enables affiliates to deploy CastleLoader, Matanbuchus, and other remote‑management tools.
No campaigns linked yet.
No observed data linked yet.
40
Techniques
40
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics