UAC-0238 is a threat actor tracked in the Ukrainian UAC naming scheme and associated with ransomware deployment via exploitation of exposed Remote Desktop Protocol services. Reported activity links the group to the delivery of multiple ransomware families, including X2anylock, Warlock, and LockBit 3.0, into already compromised environments. This indicates an intrusion pattern centered on opportunistic external access abuse followed by rapid monetization or disruptive payload deployment. The actor has been observed using exposed RDP as an initial access vector, placing it among operators that capitalize on weak perimeter exposure and insufficient remote-access hardening. Its known operations are tied to ransomware execution rather than long-form espionage tradecraft in the available reporting. The use of several distinct ransomware variants suggests operational flexibility and possible overlap with broader criminal ransomware ecosystems rather than exclusive use of a single proprietary strain. Available information directly supports initial access through exposed remote services and ransomware deployment. Broader attribution, organizational structure, sub-groups, country of origin, and victimology beyond the reported access-and-deploy pattern are not currently available at high confidence.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
2 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.