yua8186 is an underground forum persona associated with the claimed possession of a large database containing personal information on Ukrainian residents. The available reporting ties this actor to data-breach-related criminal activity centered on the advertisement or claimed holding of stolen personal data rather than to a broader, well-attributed intrusion set or state-directed campaign. Based on currently available information, yua8186 is best characterized as a data broker or breach-market actor operating in cybercriminal ecosystems. High-confidence evidence supports activity involving Ukraine as the target set, but there is insufficient corroborated information to attribute a country of origin, identify additional aliases or sub-groups, or confirm a wider operational toolkit beyond the handling and likely exfiltration or trafficking of stolen data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.