Ukrainian Cyber Alliance (UCA, also rendered UAC) is a pro-Ukraine hacktivist coalition formed from Ukrainian volunteer hacker groups including CyberHunta, Falcons Flame, Trinity, and RUH8. It emerged from collaborative activity that began after Russia’s 2014 aggression against Ukraine and was more formally established in 2016. UCA is widely described as a non-governmental or volunteer collective, but it has also been reported to have worked sporadically with, or alongside, Ukrainian armed forces and intelligence services in operations aligned with Ukraine’s wartime objectives. The group’s operations have primarily targeted Russian state, military, separatist, occupation-administration, and pro-Russian entities. Publicly attributed activity includes compromises and leaks involving Kremlin aide Vladislav Surkov, claimed operations against the Russian Ministry of Defense, attacks on separatist-linked websites and infrastructure, destructive activity against a Russian internet service provider, disruption of a postal operator serving occupied Donetsk and Luhansk, and joint operations with Black Owl against Russian drone and defense-sector organizations such as Gaskar Group. UCA has also claimed responsibility for taking down the Trigona ransomware operation by exploiting CVE-2023-22515 in exposed Confluence infrastructure, then mapping the environment, exfiltrating internal data, and wiping or defacing servers. UCA’s tradecraft spans spear-phishing, malware-enabled compromise, exploitation of public-facing vulnerabilities, persistence, internal reconnaissance, data exfiltration, destructive actions, and website defacement. Reported post-compromise behavior includes theft of internal communications, source code, administrative data, and operational records; publication of selected stolen materials; wiping of workstations, virtual infrastructure, and backups; and disruption of enterprise services. The group has also been associated with politically motivated information exposure intended to reveal Russian influence operations and support Ukrainian strategic messaging. UCA is best characterized as a pro-Ukraine hacktivist actor focused on disruptive and intelligence-supporting cyber operations against Russian and Russian-aligned targets, with occasional overlap between volunteer activism and Ukrainian state interests. Known aliases include UCA and UAC.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as part of the broader Ukraine-aligned cyber ecosystem with capability and precedent to target Russian entities, but not tied by evidence to the specific Bashkortostan dairy incidents.
Group reported as conducting operations against industrial environments.
Destructive cyberattack claimed against Donbas Post, disrupting services and destroying endpoints/VMs and large volumes of data.
Claimed disruptive/wiper-style intrusion against Donbas Post (Russian state-owned postal operator in occupied Donetsk/Luhansk), allegedly wiping >1,000 workstations, ~100 VMs, and dozens of TB of data; activity framed as hacktivism aligned with Ukraine-Russia conflict.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.