UNC5812 is a suspected Russian hybrid espionage and influence actor identified in 2024. The actor targeted potential Ukrainian military recruits through a Telegram persona branded as Civil Defense, combining malware delivery with anti-mobilization messaging and content solicitation intended to discredit Ukrainian recruitment efforts and the military more broadly. The operation used promoted posts in legitimate Ukrainian-language Telegram channels to drive victims to actor-controlled resources. Those resources advertised software purportedly designed to help users view and share locations of Ukrainian military recruiters. In practice, the campaign delivered platform-specific malware for Windows and Android, alongside a decoy mapping application tracked as SUNSPINNER. Analysis indicated the mapping functionality was not genuinely crowdsourced and primarily served as a lure supporting the broader operation. On Windows, UNC5812 used a multi-stage infection chain involving Pronsis Loader and follow-on components that ultimately deployed the PURESTEALER infostealer. PURESTEALER is designed to steal browser credentials, cookies, cryptocurrency wallet data, and information from messaging and email clients. On Android, the actor delivered a variant of CRAXSRAT and used social engineering to persuade victims to sideload the application, disable Google Play Protect, and grant extensive permissions. CRAXSRAT provided backdoor and surveillance capabilities including file and SMS management, contact and credential harvesting, and monitoring of location, audio, and keystrokes. Beyond malware delivery, UNC5812 solicited videos alleging abuses by Ukrainian territorial recruitment centers and amplified anti-mobilization narratives aligned with broader pro-Russian influence ecosystems. This combination of espionage-oriented malware, credential and data theft, surveillance, and narrative shaping distinguishes UNC5812 as a hybrid actor operating at the intersection of cyber intrusion and information operations.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
4 malware families attributed to this actor across reporting.
16 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.