UNC4221, also tracked as UAC-0185, is a Russia-linked cyber espionage cluster assessed to operate on behalf of Russian military services. The actor has been publicly associated with broader Russian intelligence activity targeting users of commercial messaging applications, especially Signal and WhatsApp, through phishing and other social-engineering operations rather than through compromise of platform encryption. UNC4221 has targeted individuals of intelligence value, including current and former U.S. government officials, allied government personnel, military leaders and service members, political figures, journalists, diplomats, policy specialists, researchers focused on Russia and security affairs, nongovernmental organizations supporting Ukraine, and key officials in Ukraine. Reporting also places the cluster within Russian operations focused on battlefield technology, secure communications, and direct attacks on Ukrainian and allied defense assets. Its tradecraft includes impersonation of messaging-platform support accounts, spoofed account-security or synchronization warnings, and lures designed to obtain verification codes, account PINs, and increasingly Signal Backup Recovery Keys. UNC4221 has also been linked to abuse of legitimate device-linking features and to modified invitation workflows that connect attacker-controlled devices to victim accounts. These methods enable access to sensitive conversations, contact lists, group chats, and historical message archives, and can support follow-on phishing from compromised trusted accounts. In the Signal-focused activity, theft of Backup Recovery Keys can provide durable access to archived communications even after account recreation unless the victim rotates the recovery key. The actor’s operations are consistent with intelligence collection and post-compromise exploitation against high-value targets, particularly in the context of Russia’s interests in Ukraine and allied government and defense ecosystems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linked to widespread phishing campaigns targeting Signal users.
Conducting phishing/social-engineering operations to seize Signal accounts by impersonating support staff and tricking high-value targets into sharing backup recovery keys, verification codes, or account PINs.
Conducting a phishing campaign against Signal users by impersonating Signal support to steal Backup Recovery Keys, and previously seeking account verification codes and Signal PINs.
Russia-linked hacking group identified as working on behalf of Russian military services; cited as one of the two groups involved in the ongoing activity described in the advisory.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.