UNC5125, also tracked as FlyingYeti and UAC-0149, is a Russia-linked threat cluster focused on highly targeted operations against Ukrainian frontline drone units and related battlefield technology. The actor is associated with campaigns supporting Russian military objectives in the Russia-Ukraine war and is part of a broader set of Russian intrusion clusters targeting Ukrainian and allied defense assets, secure communications, and operational military systems. UNC5125 has specialized in social engineering and malware delivery aimed at drone operators and military personnel. Reported activity includes the use of Google Forms-hosted questionnaires to reconnoiter prospective drone operators and the delivery of malware through messaging applications. The group has used MESSYFORK, also known as COOKBOX, and GREYBATTLE, an Android malware described as a bespoke variant of Hydra, to compromise victims. GREYBATTLE has been used to steal credentials and other data from targeted Android devices, and delivery infrastructure has included spoofed military- or defense-themed web properties. The actor’s operations indicate a focus on reconnaissance, initial access, credential theft, and post-compromise collection against battlefield-relevant mobile and communications environments. Its targeting of frontline drone units reflects a tactical intelligence mission aligned with Russian espionage requirements rather than financially motivated crime. Known aliases include FlyingYeti and UAC-0149.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russian cluster described as focusing on battlefield technology, secure communications, and attacks on Ukrainian and allied defense assets.
Targeting of frontline Ukrainian drone units using Google Forms-based lures to deliver malware.
Highly targeted operations against Ukrainian frontline UAV/drone units, combining reconnaissance (questionnaires) with malware delivery via messaging apps and spoofed websites to steal credentials/data.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.