UWORK is a criminal service provider in the pig-butchering-as-a-service ecosystem that supplies content and agent-management tooling for online investment fraud operations. It is associated with turnkey scam enablement rather than a standalone intrusion set or nation-state campaign. Its offerings include prebuilt templates for fraudulent investment websites designed to help operators rapidly deploy convincing scam portals at low cost and manage victim-facing agents at scale. The tooling associated with UWORK supports core fraud operations through website content management and agent administration. Reported functionality in this ecosystem includes investment-site templates, know-your-customer collection workflows used to solicit identity documents from victims, and administrative panels that provide centralized operational oversight. Such panels can support user and agent management, hierarchical affiliate-style agent structures, communications tracking, and profitability monitoring, enabling organized scam centers to coordinate large numbers of operators. UWORK fits into a broader specialization trend in which service providers lower barriers to entry for romance-baiting and investment scams by selling modular infrastructure, management platforms, and related operational support. Its role is best characterized as enabling initial victim engagement, social-engineering operations, and downstream collection of victim data for financial fraud. High-confidence reporting supports UWORK as a seller of scam-site content and agent-management tools; additional attribution, geography, and victimology are not currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.