UAC-0263 is a Ukrainian-tracked threat actor conducting mobile-focused operations against Ukrainian users. It distributes malicious Android applications through decoy websites masquerading as services such as air-raid-alert applications and fuel-discount offers. The activity has been associated with BTMOB, Android malware that provides remote access to compromised devices and enables theft of victim information. UAC-0263’s use of convincing service-themed lures is intended to induce targets to install malicious applications, providing initial access to mobile devices and supporting subsequent data collection.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
4 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Distributes the CamelSpy Android spyware application to steal device and user information from Ukrainian targets.
Conducts Android malware distribution campaigns using decoy service applications. BTMOB provides remote access to infected devices and enables information theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.