UAC-0247 is a cyber threat cluster tracked by CERT-UA that has conducted an active campaign against Ukraine since early 2026. The cluster has primarily targeted Ukrainian local government bodies, municipal authorities, municipal healthcare institutions, clinical hospitals, emergency medical services, and emergency hospitals. It has also targeted representatives of Ukraine’s Defense Forces and FPV drone operators. The actor’s activity is consistent with espionage-focused intrusions, with additional opportunistic abuse of compromised systems for cryptocurrency mining observed in at least some incidents. UAC-0247 commonly gains initial access through phishing lures themed around humanitarian aid proposals or related discussions. Victims are directed to malicious links that lead to archive downloads, often via AI-generated fake websites or compromised legitimate websites abused to deliver malicious content. The infection chain typically relies on archive-contained shortcut files that trigger HTA-based execution, decoy content, scheduled tasks, shellcode injection into legitimate processes, and staged payload delivery. In separate activity against FPV drone operators, the cluster used trojanized software distributed via Signal and DLL side-loading to deploy malware. The cluster has used AGINGFLY as a core malware family. AGINGFLY is a C# remote access tool that supports command execution, file download, screenshot capture, keylogging, arbitrary code execution, and remote control of infected systems. A notable design feature is its retrieval of command handlers from command-and-control infrastructure as source code, followed by dynamic compilation on the victim host at runtime. UAC-0247 has also used SILENTLOOP for persistence and command execution, including retrieval of updated command-and-control information from Telegram; RAVENSHELL or a TCP reverse shell as staging or access tooling; CHROMELEVATOR to steal credentials and other sensitive data from Chromium-based browsers; and ZAPIXDESK to extract WhatsApp data. Additional tooling observed in victim environments includes RustScan for network scanning and Ligolo-ng and Chisel for covert tunneling. Observed post-compromise behavior includes credential theft, keylogging, reconnaissance, scanning, lateral movement, persistence, covert tunneling, and broader post-exploitation activity. The actor has stolen sensitive data from browsers and WhatsApp for Windows and has conducted internal network discovery after initial compromise. In at least one case, compromised infrastructure was also used to run cryptocurrency-mining software, indicating secondary monetization or resource abuse alongside espionage objectives. UAC-0247 was previously tracked as UAC-0244.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
296 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
13 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat activity cluster targeting Ukrainian drone operators with ZIP-delivered HTA droppers and a backdoor that establishes a reverse shell.
Espionage campaign targeting Ukrainian hospitals, municipal authorities, and emergency medical services, attempting to steal sensitive data and in some cases use compromised systems for cryptocurrency mining.
Conducting phishing-based malware campaigns in Ukraine targeting local governments and healthcare providers, using humanitarian assistance lures to deliver AgingFly for data theft.
Conducting phishing-led intrusions against Ukrainian local government, municipal healthcare, Defense Forces representatives, and FPV drone operators to steal browser and WhatsApp data, perform network reconnaissance, establish persistence and tunneling, and maintain remote access.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.