UAC-0002 is a Russian state-linked threat actor associated with Sandworm, also tracked as APT44 and Seashell Blizzard. It has conducted sustained, targeted cyber operations against Ukraine, including government, military, and critical infrastructure entities, and is linked to both espionage and destructive activity. UAC-0145 has been identified as a subcluster of UAC-0002. The actor has used multiple initial access vectors over time. Documented approaches include trojanized software installers masquerading as Microsoft Windows or Microsoft Office software and distributed through torrent ecosystems; social-engineering operations conducted through Signal, often impersonating antivirus or protective software and in some cases maintaining prolonged interaction with victims; and ClickFix-style infection chains delivered through compromised websites that present fake CAPTCHA prompts and trick users into executing PowerShell commands. At least some compromises obtained through these methods were later used for persistence and lateral movement inside victim environments and enabled destructive attacks against Ukrainian government infrastructure. UAC-0002 has employed a diverse malware and tooling ecosystem. Malware associated with these operations includes KALAMBUR, SUMBUR, TAMBUR, GHETTOVIBE, SCOUTCURL, FLUIDLEECH, LOADLOOP, FREAKYPOLL, and the Android backdoor COWARDDUCK. SCOUTCURL has been used for host reconnaissance and data collection, while FLUIDLEECH and LOADLOOP function as loaders. FREAKYPOLL is a Python-based backdoor. COWARDDUCK, distributed as a fake protective Android application, is capable of collecting device information, contacts, files, and real-time geolocation. The actor has also relied on legitimate tools such as OpenSSH, Tor, and rsync to maintain unauthorized remote access, tunnel traffic, and exfiltrate stolen data, including messenger content. Web-based delivery infrastructure in these campaigns has included traffic-filtering and content-manipulation components such as Cloaking.House and SMARTAXE. These mechanisms have been used to selectively present malicious content, inject fake verification prompts, and dynamically retrieve remote infrastructure details, including through blockchain smart-contract lookups. The group has also targeted communications data, including theft of keys and messenger data from Signal and WhatsApp. UAC-0002 has additionally been associated with targeted use of malicious Microsoft Excel XLL add-ins in attacks against Ukrainian organizations, including critical infrastructure. This tradecraft has been referenced in connection with later activity tracked separately under UAC-0245, indicating prior UAC-0002 experience with XLL-based intrusion chains. Overall, UAC-0002 is characterized by adaptive social engineering, multi-platform malware development, abuse of legitimate administration tools, and a demonstrated capacity to translate initial compromise into long-term access, lateral movement, intelligence collection, and destructive effects.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
35 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
21 malware families attributed to this actor across reporting.
16 additional families tracked in Mallory.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Named subcluster associated in the report with UAC-0145 and identified as the broader Sandworm/APT44/Seashell Blizzard activity set behind the described campaigns against Ukraine.
Referenced as a separate CERT-UA tracked cluster previously observed using XLL files in targeted attacks against Ukrainian critical infrastructure; mentioned for differentiation from UAC-0245 rather than as the primary actor in this report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.