UAC-0239
UAC-0239 is a threat cluster tracked by CERT-UA that has conducted spearphishing campaigns targeting the Defence Forces of Ukraine and local state/government agencies across multiple Ukrainian regions. CERT-UA observed this activity from at least the second half of September 2025. The group impersonates the Security Service of Ukraine (SSU) and uses lure themes related to “countering russian sabotage-reconnaissance groups.” Observed delivery methods include phishing emails sent from UKR.net and Gmail accounts containing links to password-protected archives or directly attached VHD files. The VHD files contained an executable and decoy PDF documents. In these campaigns, UAC-0239 used the publicly available Go-based OrcaC2 framework and a Go-based stealer named FILEMESS. FILEMESS searches Desktop, Downloads, Documents, and logical drives for files with targeted extensions, computes MD5 hashes, and exfiltrates collected files to Telegram via the Telegram API. FILEMESS also establishes persistence via a Windows Registry Run key and uses XOR-obfuscated, Base64-encoded Telegram credentials. OrcaC2 capabilities referenced in the reporting include remote code execution, interactive shell access, file transfer, screenshots, keylogging, process control including memory dumps, UAC bypass, shellcode execution, process injection, proxy/SOCKS support, SSH and SMB tunneling, port scanning, password brute-forcing, and persistence mechanisms such as scheduled tasks, Run registry entries, and services. Known alias in the provided content: uac_0239.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- defense
- government
Associated malware families
2 malware families attributed to this actor across reporting.
Recent activity
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Phishing-led intrusions against Ukrainian defense forces and local government using VHD-based delivery to deploy a Go stealer (FILEMESS) and OrcaC2 for post-compromise control, with exfiltration to Telegram.
UAC-0239 is conducting phishing campaigns impersonating Ukrainian intelligence services to target local governments and military entities in Ukraine.
Targeted spearphishing campaign against Ukraine’s Defence Forces and local government bodies, impersonating the Security Service of Ukraine and delivering payloads via archives/VHDs to deploy OrcaC2 C2 framework and FILEMESS data-stealer (exfiltration via Telegram).
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.