UAC-0227 is a Russia-linked threat cluster tracked for cyber operations against Ukraine and observed active since at least March 2025. The group has conducted phishing campaigns primarily targeting Ukrainian local authorities, critical infrastructure facilities, and Territorial Recruitment and Social Support Centers, with additional reporting indicating interest in communications-related public-sector entities and earlier activity affecting European Union countries. UAC-0227 is associated with espionage-oriented intrusion activity centered on credential and data theft rather than destructive or ransomware-driven operations. Its campaigns have used social engineering delivered through phishing emails, including ClickFix-style lures and SVG attachments that execute in a browser context to deliver commodity stealer malware such as Amatera Stealer and Strela Stealer. Reported objectives include collection of credentials and other victim data from targeted organizations. The cluster fits the broader pattern of Russian cyber operations aligned against Ukrainian state and critical sectors. Known targeting overlaps include local government and critical infrastructure, and the actor’s tradecraft emphasizes initial access through phishing, use of malicious attachments, and follow-on theft of information from compromised systems. No high-confidence sub-groups or widely used alternative aliases beyond UAC-0227 are established in the available reporting.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
UAC-0227 conducts espionage against Ukrainian local governments, critical infrastructure, and communications entities, using email-based delivery of ransomware via SVG files. Past activity also targeted EU countries.
Phishing campaigns targeting Ukrainian local authorities and critical infrastructure using ClickFix-style lures and SVG attachments to deliver commodity stealers.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.