UAC-0239 is a threat cluster tracked by CERT-UA for spearphishing operations targeting Ukrainian defense forces and local government bodies. The actor has conducted campaigns since at least the second half of September 2025 and has impersonated the Security Service of Ukraine in lures themed around countering Russian sabotage and reconnaissance groups. Observed delivery methods include phishing emails sent through common webmail services, with links to archives or direct attachments containing VHD files that package an executable alongside decoy documents. UAC-0239 has been associated with the deployment of FILEMESS, a Go-based stealer focused on collecting documents from user directories and additional logical drives and exfiltrating them through Telegram. FILEMESS has also been observed establishing persistence on compromised Windows systems. The actor has additionally used OrcaC2, an open-source Go-based command-and-control framework that supports remote code execution, interactive shell access, file transfer, screenshots, keylogging, process control, process injection, UAC bypass, proxying and tunneling, port scanning, password brute-forcing, and multiple persistence options. Taken together, the observed tradecraft indicates a capability set centered on initial access via spearphishing, data theft, persistence, and broad post-compromise operator control. High-confidence reporting ties UAC-0239 activity to Ukrainian military and local state institutions. No high-confidence attribution to a specific nation state or country of origin is established here.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
2 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions against Ukrainian defense forces and local government using VHD-based delivery to deploy a Go stealer (FILEMESS) and OrcaC2 for post-compromise control, with exfiltration to Telegram.
UAC-0239 is conducting phishing campaigns impersonating Ukrainian intelligence services to target local governments and military entities in Ukraine.
Targeted spearphishing campaign against Ukraine’s Defence Forces and local government bodies, impersonating the Security Service of Ukraine and delivering payloads via archives/VHDs to deploy OrcaC2 C2 framework and FILEMESS data-stealer (exfiltration via Telegram).
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.