Also known as: UAC-0255, tracked as, 27, 2026, cpyy, APT3, Gothic Panda, UPS Team, DeputyDog, Parastoo, defense technology, military, diplomacy sectors, APT28, Pawn Storm, Fancy Bear, MiniDionis, Chinastrats, TG-0110, Newscaster, Sednit, Hammertoss, Patchwork
Cyber Serp is a threat actor that has gained prominence through targeted phishing operations against governments, defense contractors, and other high‑value sectors in the United States, Ukraine, and numerous EU, Middle Eastern, and Asian countries. The operator’s most recent campaign (UAC‑0255) spoofed Ukrainian CERT alerts, urging recipients to download a password‑protected ZIP file from Files.fm. Once accessed, the archive triggered an IRONHALO downloader that installed the age‑based remote access trojan AGEWHEEZE and enabled further payload delivery via WebSocket C&C channels on port 8443. Attackers also exploited known Microsoft Word use‑after‑free bugs and CVE‑2015‑1701 for local privilege escalation, allowing them to modify registry keys and scheduled tasks to maintain persistence. In addition to the phishing vector, Cyber Serp has been linked to a broader suite of tools reminiscent of APT29’s “Duke” family (MiniDuke, CosmicDuke, OnionDuke, etc.), which it uses for rapid break‑ins (“smash‑and‑grab”) as well as long‑term intelligence gathering. The actor gathers user data through screenshot capture, clipboard monitoring, and keystroke logging before exfiltrating information over the same WebSocket C&C channel using encrypted traffic. Defensive detection hinges on identifying self‑signed certificates with anomalous organization fields, outbound HTTPS to OVH hosts on nonstandard ports, and the characteristic password‑protected ZIP attachments used in this campaign. Cyber Serp’s operations show a blend of quick attacks aimed at large data volumes followed by patient, stealthy footholds designed to harvest ongoing intelligence. While most documented activity focuses on Ukrainian targets, historical evidence suggests outreach toward U.S., European, and Asian defense establishments, with a particular emphasis on diplomatic and intelligence agencies.
Targeted Sectors
Targeted Countries / Regions
Executive Summary
Cyber Serp (also known as UAC‑0255 and linked to a larger family of APT29-like actors) is a sophisticated cyber‑espionage outfit that specializes in high‑profile spear‑phishing campaigns. By masquerading as Ukrainian CERT notices and using password‑protected ZIP archives hosted on Files.fm, it delivers the Go‑based RAT AGEWHEEZE along with ancillary downloaders such as IRONHALO and ELMER. The group employs advanced persistence mechanisms, a WebSocket C2 over port 8443 on OVH servers, and exploits CVE‑2015‑1701 to secure long‑term access for extensive data exfiltration.
Goals & Targeting
The actor’s overarching goal is long‑term espionage against state‑sponsored entities within the defense, diplomacy, and strategic sectors. By leveraging trusted identifiers (CERT UA branding) and low‑profile delivery mechanisms (Files.fm archives), Cyber Serp seeks to infiltrate privileged networks for sustained data exfiltration. Strategic targeting prioritizes national security organizations in the U.S., EU countries, and regional powers such as Russia, Iran, and China, reflecting a focus on geopolitical adversaries and allies of their sponsors.
Enhanced Description
Key Capabilities
MITRE ATT&CK Tactics
ATT&CK Techniques
Software / Tooling
Campaigns & Victims
Cyber Serp’s campaigns exhibit a high‑frequency, low‑profile approach that begins with an enticing spear‑phishing attachment. After initial compromise, the actor rapidly harvests data and optionally installs additional backdoors to maintain long‑term access. Their operations have spanned multiple continents, targeting governmental, defense, financial, legal, aerospace, maritime, and energy sectors. Past high‑profile incidents include the UAC‑0255 phishing campaign directed at Ukrainian public and private organizations, as well as historical ties to APT29’s ‘Duke’ malware family used against U.S. government entities in 2015.
IOC Patterns
Recommended Actions
Suggested Tags
Confidence Assessment
The confidence in the core campaign facts (phishing vectors, use of AGEWHEEZE, impersonation of CERT‑UA) is high due to corroborating reports from multiple security vendors and government advisories. Details about the full toolset breadth, exact operational timelines, and attribution evidence linking Cyber Serp to specific national sponsors remain limited, which introduces uncertainty regarding long‑term objectives and geopolitical motivations. Further intelligence collecting on command‑and‑control infrastructure and credential reuse patterns would help refine risk assessments.
No campaigns linked yet.
No observed data linked yet.
11
Techniques
53
Tools
0
Campaigns
23
IOCs
0
Observed Data
7
Tactics