UAC-0219 is a cyberespionage threat cluster tracked by Ukrainian defenders and assessed as Russia-linked. The group has been active since at least late 2024 and was observed conducting increased operations during 2025 against Ukrainian state administration bodies, local authorities, military-related entities, and critical infrastructure. Its activity fits a wartime intelligence-collection mission focused on rapid theft of information rather than long-term covert access. UAC-0219 is associated with the WRECKSTEEL malware family, a PowerShell-based backdoor and data-stealing tool used to collect victim data and capture screenshots. Reporting also links the operation to AI-assisted development, with indications that some PowerShell components were generated or refined using AI tools. The broader operational pattern attributed to Russia-linked actors during this period emphasizes shorter intrusions, rapid collection, and exit rather than durable persistence, and UAC-0219 aligns with that model. High-confidence observed capabilities include initial access in espionage campaigns, post-compromise data theft, screenshot collection, and exfiltration. The cluster is part of the wider set of Russia-linked operations targeting Ukraine during the ongoing war, including attacks against critical sectors and public-sector institutions.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAC-0219 is conducting data theft and surveillance operations against Ukrainian entities, using AI-generated scripts and the WRECKSTEEL malware.
Cyberespionage activity cluster reported by CERT-UA, associated with use of the Wrecksteel backdoor and AI-assisted components (e.g., AI-based PowerShell scripts). The reporting also notes a shift toward shorter intrusion windows, use of information-stealing tooling, and exploitation of zero-click flaws, with operations synchronized with kinetic strikes for disruption.
Conducting malware-based intrusions against Ukrainian state administration bodies and critical infrastructure; used PowerShell data-stealing malware WRECKSTEEL, with indications of AI-assisted development.
Cyberespionage activity attributed with using AI-assisted malware development, specifically AI-generated PowerShell scripting within the Wrecksteel malware, in operations targeting Ukraine.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.