UAC-0219 is a cyberespionage threat cluster tracked by Ukrainian defenders and assessed as Russia-linked. The group has been active since at least late 2024 and was observed conducting increased operations during 2025 against Ukrainian state administration bodies, local authorities, military-related entities, and critical infrastructure. Its activity fits a wartime intelligence-collection mission focused on rapid theft of information rather than long-term covert access. UAC-0219 is associated with the WRECKSTEEL malware family, a PowerShell-based backdoor and data-stealing tool used to collect victim data and capture screenshots. Reporting also links the operation to AI-assisted development, with indications that some PowerShell components were generated or refined using AI tools. The broader operational pattern attributed to Russia-linked actors during this period emphasizes shorter intrusions, rapid collection, and exit rather than durable persistence, and UAC-0219 aligns with that model. High-confidence observed capabilities include initial access in espionage campaigns, post-compromise data theft, screenshot collection, and exfiltration. The cluster is part of the wider set of Russia-linked operations targeting Ukraine during the ongoing war, including attacks against critical sectors and public-sector institutions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAC-0219 is conducting data theft and surveillance operations against Ukrainian entities, using AI-generated scripts and the WRECKSTEEL malware.
Cyberespionage activity cluster reported by CERT-UA, associated with use of the Wrecksteel backdoor and AI-assisted components (e.g., AI-based PowerShell scripts). The reporting also notes a shift toward shorter intrusion windows, use of information-stealing tooling, and exploitation of zero-click flaws, with operations synchronized with kinetic strikes for disruption.
Conducting malware-based intrusions against Ukrainian state administration bodies and critical infrastructure; used PowerShell data-stealing malware WRECKSTEEL, with indications of AI-assisted development.
Cyberespionage activity attributed with using AI-assisted malware development, specifically AI-generated PowerShell scripting within the Wrecksteel malware, in operations targeting Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.