UAC-0184
UAC-0184 is a Russia-aligned threat actor, also tracked as Hive0156, UNC5435, MB-0005, and MB-0007. Reporting in the provided content consistently describes the group as conducting cyber-espionage operations primarily against Ukrainian military and government entities, especially representatives of the Defense Forces of Ukraine, and in some cases the Verkhovna Rada. CERT-UA reported increased activity during 2024 focused on gaining access to victims’ computers in order to steal documents and messenger data. The group relies heavily on social engineering and messenger-based delivery. Reported initial access vectors include popular messengers, dating websites, and specifically Viber, as well as lures themed around criminal or enforcement proceedings, combat videos, military administration, compensation issues, and acquaintance or romance pretexts. Multiple campaigns used ZIP archives containing malicious LNK files disguised as documents, spreadsheets, images, PDFs, DOCX, RTF, or XLSX files. Observed tradecraft includes LNK-based execution, PowerShell downloader chains, use of bitsadmin and mshta to retrieve and execute HTA payloads, and staged delivery through ZIP archives. The content describes repeated use of DLL side-loading and search-order hijacking with legitimate software as cover, including Plane9 components, Microsoft-signed VSLauncher.exe, Bitdefender Endpoint Security deployer bddeploy.exe, OneDrive-themed ClusterHub.exe, and executables associated with PassMark BurnInTest or PassMark Endpoint. Payload staging and reconstruction techniques directly mentioned in the content include XOR decoding, AES-256-CBC decryption, gzip decompression, LZNT1 decompression, reflective loading of .NET assemblies, pseudo-PNG/IDAT chunk parsing, in-memory payload reconstruction, and module stomping. Malware and tooling directly associated with UAC-0184 in the provided content include HijackLoader/IDATLoader, SHADOWLADDER, GHOSTPULSE, Remcos RAT, ViottoKeylogger, XWorm, SIGTOP, and TUSC. CERT-UA states SIGTOP and TUSC are used to steal and exfiltrate data from compromised systems, including Signal messages and contact data. Several analyses in the content describe HijackLoader or related IDAT-based loaders ultimately deploying Remcos RAT. Other reporting in the content links the actor to XWorm and Remcos in multi-stage attacks. The actor’s targeting and objectives, as directly stated in the content, are intelligence gathering and theft of documents and messenger data from Ukrainian military- and government-related victims. The content also notes use of geofenced or gated payload delivery in some campaigns and repeated use of military-themed decoys to match the victim set.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Military
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Tradecraft
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
Observables
253 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a Ukraine-themed malware delivery campaign using LNK files, temporary VBScript and PowerShell downloaders, a OneDrive-themed DLL sideload chain, HijackLoader/IDATLoader, and a final Remcos RAT payload.
Targeting Ukrainian military-related entities using LNK lure files to deliver an executable associated with the legitimate PassMark BurnInTest program.
Conducting a targeted malware campaign against Ukraine, particularly military-related targets and individuals connected to the Ukrainian Defence Forces, using social engineering lures, bitsadmin, HTA execution, DLL sideloading, and repurposed legitimate signed software for covert command-and-control.
Conducting espionage-focused intrusions against Ukrainian military-related targets, using messenger and dating-platform social engineering, Ukraine-themed lures, staged malware delivery, HTA/LNK chains, DLL sideloading, and document/messenger data theft.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.