UNC4221, also tracked as UAC-0185, is a Russia-linked cyber-espionage threat cluster assessed to operate on behalf of Russian military services. The actor has been publicly associated with campaigns targeting secure messaging accounts, especially Signal and WhatsApp, through social engineering rather than cryptographic compromise of the platforms themselves. Reported victimology includes current and former U.S. government officials, allied government and military personnel, journalists, political figures, and key officials in Ukraine, with broader targeting tied to intelligence collection against Ukraine, Europe, and the United States. A core UNC4221 tradecraft pattern is phishing that impersonates messaging-platform support personnel or automated support accounts to obtain account verification codes, PINs, and increasingly Signal Backup Recovery Keys. By coercing victims into enabling backups and disclosing recovery material, the actor can restore encrypted backups on attacker-controlled devices, access historical private and group conversations, and in some cases facilitate durable account compromise even after victims recreate accounts using the same phone number unless the recovery key is rotated. UNC4221 has also been linked to abuse of legitimate device-linking features and malicious QR-code or invite-link workflows to attach attacker-controlled devices to victim messaging accounts, enabling access to conversations and follow-on phishing from trusted identities. The cluster has shown a particular focus on Ukrainian targets and secure communications used in the Russia-Ukraine war context, including Signal accounts used by Ukrainian military personnel. Reporting also links UNC4221 to Android-focused intrusion activity involving STALECOOKIE and delivery of the TINYWHALE downloader via ClickFix, followed by deployment of MeshAgent for remote access. Across observed operations, UNC4221 demonstrates capabilities in initial access, credential theft, session or account hijacking through linked-device abuse, persistence via continued account access, post-exploitation access to communications, and exfiltration of sensitive message content and related data. The actor’s dominant motivation is espionage.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
15 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
5 malware families attributed to this actor across reporting.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Conducting phishing/social-engineering operations to seize Signal accounts by impersonating support staff and tricking high-value targets into sharing backup recovery keys, verification codes, or account PINs.
Conducting a phishing campaign against Signal users by impersonating Signal support to steal Backup Recovery Keys, and previously seeking account verification codes and Signal PINs.
Russia-linked hacking group identified as working on behalf of Russian military services; cited as one of the two groups involved in the ongoing activity described in the advisory.
Russian state-linked threat group operating on behalf of Russian military services and involved in phishing and social engineering campaigns against Signal and WhatsApp users tied to U.S. and allied interests.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.