UAC-0184 is a Russia-aligned cyber-espionage threat actor focused primarily on Ukrainian military and government targets, especially representatives of the Defense Forces of Ukraine and related state institutions. The actor is also tracked as Hive0156 and has been associated in some reporting with UNC5435 and Malwarebox cluster identifiers such as MB-0005 and MB-0007. Its operations are characterized by socially engineered lures tailored to wartime Ukrainian themes, including military administration, criminal proceedings, combat footage, compensation matters, and personal or romantic pretexts designed to build trust with targets. The group commonly uses messaging platforms rather than traditional email as an initial access vector, including Viber and other popular messengers, and has also used dating platforms and direct social-contact approaches. Delivery frequently relies on ZIP archives containing weaponized Windows shortcut files masquerading as documents, images, spreadsheets, or PDFs. Observed execution chains use native Windows tooling such as cmd, PowerShell, bitsadmin, mshta, VBScript, and HTA payloads to stage follow-on malware. UAC-0184 has repeatedly employed multi-stage loader chains built around DLL side-loading and abuse of legitimate signed software. Reported chains include use of HijackLoader and related IDAT-based loaders, as well as SHADOWLADDER and GHOSTPULSE at initial infection stages. The actor has hidden encrypted payloads inside pseudo-PNG or IDAT-like containers, then reconstructed them in memory using XOR decoding, AES decryption, gzip decompression, and LZNT1 decompression. Campaigns have used legitimate software covers and sideload hosts associated with products such as Plane9, Microsoft Visual Studio components, Bitdefender deployment tooling, OneDrive-themed binaries, and PassMark BurnInTest or PassMark Endpoint components. The actor’s malware set includes Remcos RAT, XWorm, ViottoKeylogger, SIGTOP, and TUSC. Remcos has been a recurring final payload in multiple campaigns and has been used to establish remote access and support intelligence collection. XWorm and keylogging capabilities have also been reported. SIGTOP and TUSC have been used to steal and exfiltrate documents, messenger data, and in particular Signal messages and contact data, reflecting the actor’s focus on communications intelligence from Ukrainian military personnel. Tradecraft attributed to UAC-0184 includes spearphishing, initial access via social engineering, credential-adjacent collection of messenger content, persistence through scheduled tasks and registry autoruns, DLL side-loading, reflective loading, process injection or module stomping, defense evasion through trusted-process abuse and gated payload delivery, and post-compromise exfiltration. Some campaigns also showed multicast and TCP communications through repurposed legitimate software components, suggesting efforts to blend command-and-control behavior with benign-looking network activity. The actor’s dominant objective is espionage: gaining access to victim systems used by Ukrainian defense and government personnel in order to steal documents, communications, and other sensitive operational information. Available reporting consistently places UAC-0184 within the broader pattern of Russian cyber operations supporting intelligence collection against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
39 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
253 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting a Ukraine-themed malware delivery campaign using LNK files, temporary VBScript and PowerShell downloaders, a OneDrive-themed DLL sideload chain, HijackLoader/IDATLoader, and a final Remcos RAT payload.
Targeting Ukrainian military-related entities using LNK lure files to deliver an executable associated with the legitimate PassMark BurnInTest program.
Conducting a targeted malware campaign against Ukraine, particularly military-related targets and individuals connected to the Ukrainian Defence Forces, using social engineering lures, bitsadmin, HTA execution, DLL sideloading, and repurposed legitimate signed software for covert command-and-control.
Conducting espionage-focused intrusions against Ukrainian military-related targets, using messenger and dating-platform social engineering, Ukraine-themed lures, staged malware delivery, HTA/LNK chains, DLL sideloading, and document/messenger data theft.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.