Also known as: TAG-160, TAG-161, TAG-150, a technically sophisticated, impersonates Booking.com, Matanbuchus, tracked as, uncashed checks, impersonates global logistics firms, using phishing lures, impersonates logistics firms, while spoofing legitimate emails, abusing freight-matching platform, leverages Booking.com-themed lures, RefBroker, Qakbot, other threat actors, BokBot, stale dated checks
UAC‑0241 emerged in 2025, with a sophisticated blend of social engineering and technical exploits. It capitalizes on high-credibility brand impersonation—booking.com, logistics carriers, government emergency services—to craft spear‑phishing emails that include password-protected ZIPs containing malicious LNK files or .URL shortcuts. These, when executed, trigger an mshta → JavaScript → PowerShell chain that deploys a suite of malware: credential harvesters such as LaZagne, file‑stealing scripts, and the Go-based GAMYBEAR backdoor. The actor leverages CastleLoader and CASTLERAT variants (Python/C) for remote command execution, file upload & delete, self‑deletion, keylogging, clipboard logging and persistence via Run‑key registry entries. Operationally, UAC‑0241 abuses freight‑matching platforms (DAT Freight & Analytics, Loadlink Technologies) and RMM tools—SimpleHelp, PDQ Connect, Fleetdeck, ScreenConnect—to funnel phishing campaigns. It additionally uses .URL shortcut files that trigger SMB requests for executables, allowing distribution of malicious payloads without direct mail attachments. The actor maintains a low‑profile, minimal footprint profile while employing techniques such as click‑fix, token impersonation and exploitation of CVE‑2018‑0824 via UnmarshalPwn. The activity reflects a MaaS model that feeds compromised infrastructure into multiple clusters, facilitating rapid scale and geographic dispersion across Ukraine, the United States, and China.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
UAC‑0241 (also known as TAG‑160/161) is a financially motivated threat actor that operates a malware-as-a-service model targeting logistics, transportation and related industries worldwide. By impersonating reputable firms such as Booking.com and freight‑matching platforms, it delivers the CastleLoader/CASTLERAT family via phishing emails, malicious URLs, and .URL shortcuts, achieving initial access, lateral movement and persistence across victim networks.
Goals & Targeting
The strategic objective is economic gain through credential theft, data exfiltration, and ransomware capabilities. By exploiting logistics and transportation sectors—often with weak email security—the actor increases hit rates on organizations that handle sensitive supply‑chain information, financial data, or government-related logistics. Its impersonation tactics also aim to erode trust in legitimate service providers. Targets span education institutions, government bodies, defense ministries, healthcare facilities, manufacturing plants, maritime operations and financial services—typically those with high-value data streams and legacy systems vulnerable to exploit chains.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
UAC‑0241 has operated since mid‑2025 with a highly modular, scalable approach. Campaigns employ a malware‑as‑a‑service model that allows rapid redirection of phishing infrastructure through compromised freight‑matching sites and RMM tools. The actor’s tempo is moderate; campaigns are released in waves after collecting sufficient reconnaissance over targeted sectors. Victim profiling focuses on supply chain and transportation organizations due to their higher susceptibility to logistics-related lures, but the actor has also successfully penetrated governmental, educational, and healthcare institutions. Notable past operations include a May‑26 spear‑phishing attack that leveraged an emergency agency spoof, leading to lateral movement across Ukrainian education networks, and recent infiltration attempts in U.S. maritime firms via .URL shortcuts. The actor’s pattern shows consistent use of CastleLoader delivery combined with bespoke post‑exploitation modules for credential theft, data exfiltration, and command & control over HTTP/S.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
Given multiple independent reports, the core facts about UAC‑0241’s impersonation tactics, CastleLoader deployment, and target sectors are high confidence. However, precise timelines, full motive analysis, and attribution beyond commercial financial gain remain uncertain due to limited public disclosure of internal investigation logs and absence of confirmed command‑and‑control infrastructure in open sources.
No campaigns linked yet.
No observed data linked yet.
49
Techniques
50
Tools
0
Campaigns
40
IOCs
0
Observed Data
13
Tactics