UAC-0194 is a threat cluster tracked in campaigns targeting Ukrainian entities and assessed with high confidence as having Russian affiliation. The group is associated with exploitation of the Windows URL-file vulnerability CVE-2024-43451, using malicious Internet Shortcut files that can trigger outbound SMB authentication through minimal user interaction and expose NTLM credentials. Reported delivery methods include phishing lures themed around academic certificate renewal and archives containing benign decoy documents alongside malicious shortcut files. Observed activity linked to UAC-0194 includes credential theft via NTLM hash capture, follow-on malware delivery, and persistence. In documented intrusions, exploitation led to retrieval and execution of additional payloads, including SparkRAT, with use of scripting and scheduled-task persistence. Reporting also notes related campaigns using the same vulnerability to deliver information-stealing malware such as RedLine Stealer, although it is not always possible to determine whether all such activity belongs to the same operator or multiple actors reusing the technique. The actor primarily targets organizations in Ukraine, especially government-related entities, and operates in a manner consistent with Russian state-aligned intrusion activity. UAC-0194 is notable for combining social engineering, low-interaction credential-harvesting techniques, malware deployment, and persistence in campaigns against Ukrainian victims.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
33 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
Microsoft created a security patch for Windows systems to fix the vulnerability, giving it the CVE identifier CVE-2024-43451. The security patch was published on November 12th, 2024.
A recently patched security flaw affecting Windows NTLM has been exploited by malicious actors to leak NTLM hashes or user passwords and infiltrate systems since March 19, 2025. The flaw, CVE-2025-24054 (CVSS score: 6.5), is a hash disclosure spoofing bug that was fixed by Microsoft last month as part of its Patch Tuesday updates. The security flaw is assessed to be a variant of CVE-2024-43451 (CVSS score: 6.5), which was patched by Microsoft in November 2024 and has also been weaponized in the wild in attacks targeting Ukraine and Colombia by threat actors like UAC-0194 and Blind Eagle.
26 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Associated with early use of CVE-2024-43451 in operations against Ukraine (as referenced for provenance of the vulnerability’s observed exploitation).
UAC-0194 is known for exploiting Windows NTLM vulnerabilities, specifically CVE-2025-24054 and its variant CVE-2024-43451, to leak NTLM hashes or user passwords and infiltrate systems. They have targeted Ukraine and Colombia.
Referenced as a threat actor that has weaponized CVE-2024-43451 in real-world attacks, targeting Ukraine and Colombia.
Mentioned as a Russian APT group previously linked to exploitation of CVE-2024-43451 via a .url file; in this reporting, that technique/file is reused alongside CVE-2025-24054 exploitation artifacts.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.