UNC5114 is a suspected Russian espionage cluster focused on battlefield-relevant targeting in the context of Russia’s war against Ukraine. The cluster has been associated with operations against Ukrainian and allied defense assets, with particular emphasis on battlefield technology and secure communications ecosystems used by Ukrainian forces. UNC5114 has been observed delivering a variant of the Android malware CraxsRAT while masquerading it as an update for Kropyva, a combat control and battlefield management system widely used in Ukraine. This tradecraft indicates a focus on compromising mobile devices used in operational military environments through social engineering and trojanized software updates. UNC5114 is part of a broader set of Russian intrusion clusters targeting Ukrainian military communications, battlefield management platforms, and defense-sector entities in support of intelligence collection and wartime operational objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cluster described as focusing on battlefield technology, secure communications, and attacks on Ukrainian and allied defense assets.
Android-focused distribution of a RAT by masquerading as an update to a Ukrainian military-related application (Kropyva).
Suspected Russian espionage targeting Ukrainian users via trojanized Android app updates (Kropyva-themed) to deploy commodity Android RAT capability.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.