UAC-0145 is a Russian state-sponsored threat cluster tracked by CERT-UA as a subcluster of UAC-0002, the GRU-affiliated actor known as Sandworm, APT44, and Seashell Blizzard. Its operations target Ukraine, including IT professionals, telecommunications providers, military personnel, and government infrastructure. Its activities encompass information theft, persistent unauthorized access, and lateral movement. At least one compromise originating from a trojanized software installer enabled a subsequent destructive attack against a Ukrainian central executive authority. The cluster uses multiple social-engineering and malware-delivery channels, including trojanized Microsoft Windows and Office installers distributed through torrent trackers, malicious tools shared through Signal under antivirus-protection pretexts, and ClickFix prompts on compromised websites. Its ClickFix operations use fake CAPTCHA checks to persuade visitors to execute PowerShell commands. Cloaking.House and the custom SMARTAXE tool selectively expose visitors to malicious content; SMARTAXE also uses EtherHiding to retrieve remote-resource information from an Ethereum smart contract. Associated tooling includes GHETTOVIBE, the SCOUTCURL reconnaissance script, FLUIDLEECH and LOADLOOP loaders, the FREAKYPOLL Python backdoor, and KALAMBUR, SUMBUR, and TAMBUR. The cluster abuses OpenSSH and Tor for remote access and port forwarding, and rsync for exfiltration. It steals keys and messaging data from Signal and WhatsApp. Its COWARDDUCK Android backdoor, distributed through messaging applications as a protective tool, collects device information, contacts, files, and real-time geolocation, and uses the Dropbox API for uploads. A recruitment campaign active since at least May 2026 targets Ukrainian system administrators and other IT specialists. Operators study candidates’ résumés, impersonate recruiters and IT companies, and conduct staged interviews through Telegram and Zoom. Technical assessments introduce deliberately failing VPN configurations, followed by instructions to install SopraVPN, a trojanized WireGuard-derived client distributed through SourceForge. The client decrypts concealed commands from a nonstandard configuration option using AES-256-GCM and modified Base64 decoding. Windows infections execute PowerShell, create scheduled tasks, and download additional payloads; Linux infections retrieve executables through attacker-controlled VPN infrastructure.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
57 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
11 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster attributed with the fake job offer campaign targeting administrators and IT professionals; described as a sub-cluster of Sandworm.
Conducting a recruiter-themed social-engineering campaign targeting Ukrainian IT workers, using fake job interviews and a trojanized WireGuard-based VPN client named SopraVPN to execute hidden commands and deliver follow-on payloads.
A Sandworm subgroup conducting a recruitment-themed malware campaign targeting Ukrainian system administrators and IT specialists, reportedly ongoing since May 2026. Attackers impersonate recruiters and induce candidates to install a malicious VPN client during a purported technical assessment. CERT-UA also attributed an earlier ClickFix campaign delivering data-stealing malware to this actor.
Uses advanced social engineering on job-search platforms to target IT specialists, impersonates IT companies and recruiters, conducts fake interviews over Telegram and Zoom, and delivers a trojanized WireGuard-based VPN client ('SopraVPN') to execute PowerShell or Linux payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.