UAC-0241 is a threat cluster tracked for spear-phishing operations targeting Ukrainian entities. Reported victims include educational institutions, state authorities, and residents of Ukraine’s Sumy region. The actor has used archive-based lures that deliver multi-stage infection chains beginning with a Windows shortcut file and abuse of mshta.exe to execute an HTA payload, followed by JavaScript and PowerShell stages. These campaigns have been used to deploy LaZagne for credential theft and a Go-based backdoor known as GAMYBEAR for follow-on access and post-compromise activity. The actor’s tradecraft is consistent with phishing-led initial access, staged payload delivery, and use of native Windows components to reduce detection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Spear-phishing campaign targeting Ukrainian education and state authorities using ZIP->LNK->HTA (mshta) -> JavaScript -> PowerShell chain to deploy LaZagne credential recovery and the GAMYBEAR Go backdoor.
UAC-0241 is a threat actor targeting Ukrainian residents in the Sumy region.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.