UAC-0002, also known as Sandworm, APT44, and Seashell Blizzard, is a threat actor associated with destructive cyberattacks and sustained network-compromise operations targeting Ukraine. Its targets include critical infrastructure, government institutions, military personnel, logistics providers, industrial automation suppliers, grain-handling equipment manufacturers, and IT specialists. Supplier-focused campaigns have also targeted organizations in Czechia and Serbia. CERT-UA tracks UAC-0145 and UAC-0212 as subclusters of UAC-0002 and has linked the destructive-attack planning cluster UAC-0133 to it with high confidence. The actor compromises suppliers to acquire information and access that can facilitate subsequent attacks against critical infrastructure customers. Its operations have included planning destructive attacks against Ukrainian energy, water-supply, and heating enterprises, as well as establishing access that enabled a destructive attack against a Ukrainian central executive authority. Following initial compromise, operators can move laterally within hours and establish footholds on servers, network equipment, and additional workstations. Initial-access techniques include prolonged social engineering, impersonation of prospective customers and recruiters, trojanized software installers distributed through torrent trackers, malicious Excel XLL add-ins, messenger-based lures posing as antivirus protection, and ClickFix-style fake CAPTCHA pages. Supplier campaigns have combined PDF-linked lures, exploitation of CVE-2024-38213, and disguised Windows shortcut files to execute PowerShell and deploy malware. Recruitment-themed operations have used a modified WireGuard client branded SopraVPN to execute concealed payloads on Windows and Linux. The malware ecosystem includes SECONDBEST/EMPIREPAST, SPARK, CROOKBAG, GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, SMARTAXE, and the Android backdoor COWARDDUCK. The actor uses scheduled tasks, startup mechanisms, and registry autorun entries for persistence; OpenSSH and Tor for unauthorized remote access and tunneling; and rsync for document and messenger-data exfiltration. Its collection capabilities include system reconnaissance, theft of keys and messenger data, and collection of Android files, contacts, device information, and real-time geolocation. Payload encryption, custom encoding, traffic filtering, and abuse of legitimate services support concealment and delivery.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
26 malware families attributed to this actor across reporting.
21 additional families tracked in Mallory.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
221 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as the parent/subcluster associated with UAC-0145 in this campaign.
Named subcluster associated in the report with UAC-0145 and identified as the broader Sandworm/APT44/Seashell Blizzard activity set behind the described campaigns against Ukraine.
Referenced as a separate CERT-UA tracked cluster previously observed using XLL files in targeted attacks against Ukrainian critical infrastructure; mentioned for differentiation from UAC-0245 rather than as the primary actor in this report.
The parent threat group associated with the supplier-focused activity tracked as UAC-0212. The report also describes a high-confidence connection between UAC-0002 and UAC-0133, a cluster tracking a destructive attack plan against approximately twenty Ukrainian energy, water and heat-supply enterprises. Its described subcluster operations combine supplier compromise, malware persistence and information theft to enable further access to critical infrastructure.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.