The Ukrainian Cyber Alliance (UCA), also referred to as UAC, is a Ukrainian volunteer hacktivist coalition formally established in 2016 following collaborative activity beginning in 2014. Its constituent groups include CyberHunta, Falcons Flame, Trinity, and RUH8. The alliance opposes Russian aggression against Ukraine and conducts intrusions, data disclosures, website defacements, and destructive operations against Russian and pro-Russian organizations. Its targets include government institutions, military-linked organizations, telecommunications providers, financial services, and infrastructure operators in Russian-occupied Ukrainian territory. It has collaborated with Ukrainian military intelligence, the Main Intelligence Directorate (GUR), on specific operations, while retaining its identity as a non-governmental hacktivist coalition. UCA uses spear-phishing, malware, and exploitation of internet-facing applications to compromise targets. In October 2023, it exploited CVE-2023-22515 in Atlassian Confluence to penetrate the Trigona ransomware operation, establish persistence, map its infrastructure, and exfiltrate source code, database records, and internal operational data before wiping and defacing its servers. Earlier activity included the disclosure of correspondence associated with Kremlin aide Vladislav Surkov and attacks against pro-Russian separatist websites. Its destructive campaigns include wiping systems and backups at Russian internet service provider Nodex and an attack that disrupted Donbas Post's corporate network, email, and web services. UCA has collaborated with Hacking Cat in operations using Nemo Wiper, including an attack against heating provider Donbassteploenergo in occupied Donetsk. In July 2025, it participated with Black Owl Team, also known as BO Team, and GUR in an operation against Russian drone manufacturer Gaskar. These activities combine information exposure with disruption of organizations supporting Russian state and military interests.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
5 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a participant alongside Black Owl and the GUR in a destructive cyber operation against Gaskar in July 2025. The reference provides no further information about its organization, tools, or broader activities.
A pro-Ukraine hacktivist group that collaborated with Hacking Cat to deploy the destructive Nemo Wiper malware.
Pro-Ukraine hacktivist group identified as a coordination partner of Hacking Cat in high-impact disruptive operations.
Ukraine-linked hacktivist group that collaborated with Hacking Cat in a destructive attack against a state-owned heating provider in Russian-occupied Donetsk, using Nemo Wiper.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.