UNC6096 is a Russia-linked espionage cluster focused on Ukrainian military and defense-related targets, particularly battlefield technology and secure communications. The actor has been associated with malware delivery operations conducted through WhatsApp, using lures themed around DELTA, a Ukrainian battlefield management platform, to induce victims to open a malicious shortcut file that retrieves a secondary payload. Reporting also links this activity to Android-focused malware delivery, including GALLGRAB, used to collect locally stored files, contact information, and potentially encrypted data from specialized battlefield applications. UNC6096 fits within broader Russian operations supporting military objectives against Ukraine and allied defense assets, with an emphasis on compromising frontline communications and battlefield-relevant systems.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
3 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cluster described as focusing on battlefield technology, secure communications, and attacks on Ukrainian and allied defense assets.
Malware delivery via WhatsApp targeting both Windows and Android endpoints.
Russian espionage activity delivering malware via WhatsApp using DELTA-themed lures and LNK-based initial execution to fetch additional payloads.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.