UAC-0145 is a cyber threat cluster tracked by CERT-UA and assessed as a sub-cluster of Sandworm, also known as APT44 and Seashell Blizzard, a Russian GRU-linked state-sponsored intrusion set. The cluster has targeted Ukraine, particularly Ukrainian IT workers, system administrators, military personnel, telecommunications providers, and government-related environments, and has been associated with operations supporting broader Sandworm objectives. UAC-0145 relies heavily on social engineering for initial access. Documented lures include fake recruiter outreach on job-search platforms, staged hiring processes conducted over Telegram and Zoom, and fraudulent technical tasks that require victims to install or use attacker-supplied software. In one prominent campaign, the actor impersonated legitimate IT brands and delivered a trojanized WireGuard-derived VPN client known as SopraVPN. That client introduced a malicious nonstandard configuration option, SymmetricKey, to decrypt and execute hidden commands. On Windows, this execution path created scheduled tasks and downloaded additional payloads; on Linux, it retrieved further executables through attacker-controlled infrastructure. The actor also modified Base64 handling in the client to hinder analysis. The cluster has also used ClickFix-style lures on compromised websites. Victims were shown fake CAPTCHA or verification prompts instructing them to copy and run PowerShell commands, leading to infection. Associated tooling and malware in these campaigns include GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, SMARTAXE, and the Python backdoor FREAKYPOLL. SMARTAXE was used to selectively alter compromised web pages and present malicious content only to chosen visitors, including through traffic filtering and EtherHiding-style retrieval of remote resources via blockchain smart-contract lookups. Beyond Windows and Linux tradecraft, UAC-0145 has distributed malicious Android applications disguised as security or protective tools through messenger-based social engineering. These APKs delivered the COWARDDUCK backdoor, which can collect contacts, files, and real-time geolocation data and use cloud services and legitimate platforms in its command-and-control or data-handling workflows. CERT-UA has also linked the cluster to earlier Sandworm-style access methods involving trojanized software installers, including fake Windows or Office installers from torrent ecosystems, as well as prolonged social-engineering exchanges over messaging platforms. Reported follow-on activity includes persistence, credential and messenger-data theft, exfiltration, unauthorized remote access using legitimate tools, lateral movement inside victim organizations, and enabling destructive effects against Ukrainian government infrastructure. Known aliases and related designations include Sandworm, APT44, Seashell Blizzard, and sub-cluster relationship to UAC-0002. The actor's dominant motivation is espionage in support of Russian state interests, although some operations have also facilitated disruptive or destructive outcomes.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
11 malware families attributed to this actor across reporting.
6 additional families tracked in Mallory.
57 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named activity cluster attributed with the fake job offer campaign targeting administrators and IT professionals; described as a sub-cluster of Sandworm.
Conducting a recruiter-themed social-engineering campaign targeting Ukrainian IT workers, using fake job interviews and a trojanized WireGuard-based VPN client named SopraVPN to execute hidden commands and deliver follow-on payloads.
Uses advanced social engineering on job-search platforms to target IT specialists, impersonates IT companies and recruiters, conducts fake interviews over Telegram and Zoom, and delivers a trojanized WireGuard-based VPN client ('SopraVPN') to execute PowerShell or Linux payloads.
Conducting a ClickFix campaign using fake CAPTCHA pages that trick users into running PowerShell commands, leading to reconnaissance, persistence, and deployment of multiple malware payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.