UAC-0041 is a threat cluster tracked by CERT-UA for systematic, large-scale phishing and malware-delivery activity primarily targeting Ukrainian users, organizations, and government entities. The cluster has been associated with the distribution of multiple commodity and MaaS infostealers and loaders, including AgentTesla, XLoader, Formbook, Snake Keylogger, MarsStealer, and in at least one campaign IcedID delivered via GzipLoader. CERT-UA has described the actor as focused on stealing user authentication data, while some activity attributed with moderate confidence also supported access to internal networks of Ukrainian government bodies for espionage purposes. Observed UAC-0041 operations rely heavily on phishing emails using topical lures and impersonation themes. Delivery chains have included malicious Office documents with macros, password-protected archives, executable payloads, and downloader stages that retrieve additional malware from cloud-hosted resources. In one documented campaign, a malicious spreadsheet led to GzipLoader and then IcedID. In another mass campaign, a .NET downloader known as RelicRace retrieved and memory-executed RelicSource, which decrypted embedded payloads, used process injection, implemented persistence, performed anti-analysis checks including virtual-machine detection, and ultimately deployed credential-stealing malware such as Formbook and Snake Keylogger. The malware used by UAC-0041 supports credential theft from browsers and other applications, keylogging, exfiltration of stolen data, persistence, and post-compromise payload delivery. Snake Keylogger usage linked to UAC-0041 indicates additional capabilities such as clipboard monitoring, screenshot capture, and Telegram-based exfiltration. MarsStealer use further indicates theft of browser credentials, cryptocurrency-wallet data, multi-factor-authentication application data, file theft, screenshot capture, and the ability to download and execute additional payloads. UAC-0041 has been observed in campaigns against Ukrainian citizens, domestic organizations, and government agencies, including critical government entities. The cluster’s activity has been characterized as geographically dispersed and mass in scale. Available reporting ties the broader wave of attacks against Ukrainian infrastructure during 2022 to organizations affiliated with Russian and Belarusian state or state-aligned structures, but the specific national origin of UAC-0041 itself is not established at high confidence from the available facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
17 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 malware families attributed to this actor across reporting.
2 additional families tracked in Mallory.
25 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named as one of the threat actors that has used Snake Keylogger, specifically with Formbook as a loader.
Mass phishing campaign using emails with the subject 'Остаточний платіж' delivering the .NET downloader RelicRace, which retrieves and launches RelicSource and ultimately deploys stealer malware including Formbook and Snake Keylogger.
Conducting phishing attacks against Ukrainian government agencies to deliver GzipLoader and IcedID in support of cyber-espionage and internal network access.
Credential-theft activity cluster distributing phishing emails themed as a Ukrainian Ministry of Education program, delivering MarsStealer to Ukrainian citizens and domestic organizations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.