Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0239

Also known as: TAG-160, TAG-161, TAG-150, a technically sophisticated, impersonates Booking.com, Matanbuchus, APT29, tracked as, Tech Sectors, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, RefBroker, Qakbot, other threat actors, Agrius, Masked Spider

Description

UAC-0239 has been observed conducting spearphishing attacks targeting the Defence Forces and local state agencies of Ukraine, impersonating the Security Service of Ukraine. The group employs the OrcaC2 framework and FILEMESS stealer to compromise these organizations. Their campaigns often utilize themes related to "countering russian sabotage-reconnaissance groups" to disguise their malicious intent.

Goals & Targeting

Targeted Sectors

Transportation
Defense
Government
Financial services
Energy
Education
Manufacturing
Utilities
Mining
Healthcare
Hospitality
Gaming
Non profit
Maritime

Targeted Countries / Regions

UA
US
RU
BY
JP
AZ

AI Analysis

Grounded in web research
· analyzed in 2 chunks · 9 hours ago

Executive Summary

UAC‑0239 is a financially driven threat actor that focuses on Ukrainian state institutions and a wide range of civilian sectors by leveraging spearphishing and impersonation tactics. The group uses the OrcaC2 command‑and‑control framework together with the FILEMESS infostealer to exfiltrate data, while distributing its payloads via malicious load postings on freight‑matching platforms and sophisticated ClickFix links. Their approach includes a malware‑as‑a‑service model that enables affiliates to deploy CastleLoader, Matanbuchus, and other remote‑management tools.

ATT&CK Techniques

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

  1. www.recordedfuture.com — Cited by web research for: TAG-160
  2. attack.mitre.org — Cited by web research for: Tech Sectors
  3. attack.mitre.org — Cited by web research for: T1204.002
  4. www.esentire.com — Cited by web research for: T1546.010
  5. www.group-ib.com — Cited by web research for: Cactus

Intel Summary

40

Techniques

40

Tools

0

Campaigns

40

IOCs

0

Observed Data

13

Tactics

Tags

Phishing
Backdoor / C2
Government Targeting

Details

Type
Unknown
Primary Motivation
Financial gain
Country of Origin
United States (US)
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.