Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors Cyber Serp

Also known as: UAC-0255, tracked as, 27, 2026, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork

Description

Cyber Serp is a threat actor that has gained prominence through targeted phishing operations against governments, defense contractors, and other high‑value sectors in the United States, Ukraine, and numerous EU, Middle Eastern, and Asian countries. The operator’s most recent campaign (UAC‑0255) spoofed Ukrainian CERT alerts, urging recipients to download a password‑protected ZIP file from Files.fm. Once accessed, the archive triggered an IRONHALO downloader that installed the age‑based remote access trojan AGEWHEEZE and enabled further payload delivery via WebSocket C&C channels on port 8443. Attackers also exploited known Microsoft Word use‑after‑free bugs and CVE‑2015‑1701 for local privilege escalation, allowing them to modify registry keys and scheduled tasks to maintain persistence. In addition to the phishing vector, Cyber Serp has been linked to a broader suite of tools reminiscent of APT29’s “Duke” family (MiniDuke, CosmicDuke, OnionDuke, etc.), which it uses for rapid break‑ins (“smash‑and‑grab”) as well as long‑term intelligence gathering. The actor gathers user data through screenshot capture, clipboard monitoring, and keystroke logging before exfiltrating information over the same WebSocket C&C channel using encrypted traffic. Defensive detection hinges on identifying self‑signed certificates with anomalous organization fields, outbound HTTPS to OVH hosts on nonstandard ports, and the characteristic password‑protected ZIP attachments used in this campaign. Cyber Serp’s operations show a blend of quick attacks aimed at large data volumes followed by patient, stealthy footholds designed to harvest ongoing intelligence. While most documented activity focuses on Ukrainian targets, historical evidence suggests outreach toward U.S., European, and Asian defense establishments, with a particular emphasis on diplomatic and intelligence agencies.

Goals & Targeting

Targeted Sectors

Government
Defense
Financial services
Non profit
Energy
Telecommunications
Education
Aerospace
Media
Healthcare
Information technology
Maritime
Manufacturing
Think tank
Pharmaceutical
Chemical
Mining
Hospitality
Legal services
Nuclear
Entertainment

Targeted Countries / Regions

US
UA
CN
GB
IN
JP
DE
KR
RU
IR
SA
TW
FR
CA
IL
TR
AU
KZ
PK
IT
VN
PL
AE
SG
NL
BR
ES
IQ
BY
SY
MX
RO
EG
AZ

AI Analysis

Grounded in web research
· analyzed in 3 chunks · 3 hours ago

Executive Summary

Cyber Serp (also known as UAC‑0255 and linked to a larger family of APT29-like actors) is a sophisticated cyber‑espionage outfit that specializes in high‑profile spear‑phishing campaigns. By masquerading as Ukrainian CERT notices and using password‑protected ZIP archives hosted on Files.fm, it delivers the Go‑based RAT AGEWHEEZE along with ancillary downloaders such as IRONHALO and ELMER. The group employs advanced persistence mechanisms, a WebSocket C2 over port 8443 on OVH servers, and exploits CVE‑2015‑1701 to secure long‑term access for extensive data exfiltration.

Goals & Targeting

The actor’s overarching goal is long‑term espionage against state‑sponsored entities within the defense, diplomacy, and strategic sectors. By leveraging trusted identifiers (CERT UA branding) and low‑profile delivery mechanisms (Files.fm archives), Cyber Serp seeks to infiltrate privileged networks for sustained data exfiltration. Strategic targeting prioritizes national security organizations in the U.S., EU countries, and regional powers such as Russia, Iran, and China, reflecting a focus on geopolitical adversaries and allies of their sponsors.

Enhanced Description

Key Capabilities

  • Spear‑phishing with password‑protected ZIP attachments
  • Impersonation of official CERT‑UA brand to build credibility
  • Hosting malicious archives on Files.fm service
  • Distribution of Go‑based RAT AGEWHEEZE via IRONHALO or ELMER backdoors
  • Command and Control via WebSocket channel on port 8443
  • Persistence through scheduled tasks, registry changes, and startup folder placement
  • Exploitation of Microsoft Word use‑after‑free vulnerability and CVE‑2015‑1701 for privilege escalation
  • Obfuscated files to evade detection
  • Ingress tool transfer over the C2 network
  • Monitoring user activity (screenshots, clipboard, keystrokes)
  • Rapid noisy break‑ins followed by large‑scale data exfiltration
  • Long‑term persistent compromise for intelligence gathering

MITRE ATT&CK Tactics

Initial Access
Defense Evasion
Command and Control
Persistence
Exfiltration
Privilege Escalation

ATT&CK Techniques

T1566
T1053
T1027
T1105
T1068
T1193
T1189
T1204
T1041

Software / Tooling

AGEWHEEZE
IRONHALO
ELMER
MiniDuke
CosmicDuke
OnionDuke
CozyDuke
CloudDuke (MiniDionis)
SeaDuke
HammerDuke (Hammertoss)
PinchDuke
GeminiDuke
Dropping Elephant

Campaigns & Victims

Cyber Serp’s campaigns exhibit a high‑frequency, low‑profile approach that begins with an enticing spear‑phishing attachment. After initial compromise, the actor rapidly harvests data and optionally installs additional backdoors to maintain long‑term access. Their operations have spanned multiple continents, targeting governmental, defense, financial, legal, aerospace, maritime, and energy sectors. Past high‑profile incidents include the UAC‑0255 phishing campaign directed at Ukrainian public and private organizations, as well as historical ties to APT29’s ‘Duke’ malware family used against U.S. government entities in 2015.

IOC Patterns

  • Domain names hosted on OVH servers (e.g., example.com)
  • Outbound HTTPS traffic over port 8443 with self‑signed certificates containing Organization field "TVisor"
  • Password‑protected ZIP attachments from Files.fm
  • Web page titled "The Cult" on the C2 server
  • Spear‑phishing emails with malicious attachment
  • Watering hole URLs used for initial delivery
  • Sample domains: demo-cloud.space, cisa.gov, TEMP.Hermit, TEMP.Veles, Cyber.Anarchy.Squad

Recommended Actions

  • Deploy email filtering and sandboxing tailored to detect spear‑phishing attachments
  • Implement a policy that restricts or monitors password‑protected archives in emails
  • Flag outbound HTTPS traffic on port 8443 especially towards OVH domains for deeper inspection
  • Scrutinize self‑signed certificates with unusual Organization fields and treat them as suspicious
  • Keep systems patched against CVE‑2015‑1701 and Microsoft Word use‑after‑free (EPS dictionary) vulnerabilities
  • Enable multi‑factor authentication for all privileged accounts
  • Monitor file creation in startup folders, scheduled task registry entries, and WebSocket connections to foreign hosts
  • Apply web application firewalls and DNS monitoring to detect watering hole compromises

Suggested Tags

phishing
spear-phishing
malicious-microsoft-word
exploitation-of-vulnerabilities
obfuscated-files
command-and-control
self-signed-certificate
CVE-2015-1701
EPS-dict-use-after-free
password-protected-archive
Files.fm
OVH-hosting
APT29
cyberespionage
government-targeted
watering-hole
malware-arsenal
persistent-compromise
exfiltration

Confidence Assessment

The confidence in the core campaign facts (phishing vectors, use of AGEWHEEZE, impersonation of CERT‑UA) is high due to corroborating reports from multiple security vendors and government advisories. Details about the full toolset breadth, exact operational timelines, and attribution evidence linking Cyber Serp to specific national sponsors remain limited, which introduces uncertainty regarding long‑term objectives and geopolitical motivations. Further intelligence collecting on command‑and‑control infrastructure and credential reuse patterns would help refine risk assessments.

Software / Tooling

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

References

Intel Summary

11

Techniques

53

Tools

0

Campaigns

23

IOCs

0

Observed Data

7

Tactics

Tags

Phishing
APT
espionage
Ukraine
RAT
phishing
spear-phishing
malicious-microsoft-word
exploitation-of-vulnerabilities
obfuscated-files
command-and-control
self-signed-certificate
CVE-2015-1701
EPS-dict-use-after-free
password-protected-archive
Files.fm
OVH-hosting
APT29
cyberespionage
government-targeted
watering-hole
malware-arsenal
persistent-compromise
exfiltration

Details

Type
Unknown
Primary Motivation
Espionage
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.