UAC-0252
UAC-0252 is a threat cluster tracked by CERT-UA and associated in CERT-UA reporting with individuals discussed on the Telegram channel "PalachPro." The activity targets Ukraine, including Ukrainian government institutions, central executive authorities, and regional administrations, and uses phishing emails impersonating Ukrainian government bodies and regional administrations. Lures have included themes related to updating widely used civilian and military mobile applications and documents impersonating Ukrainian government institutions, including the Bureau of Economic Security of Ukraine. CERT-UA reported repeated campaigns beginning in January 2026. Delivery methods included attached archives containing EXE payloads and links to legitimate but XSS-vulnerable websites that executed JavaScript and downloaded executables. GitHub-hosted payloads and scripts were used in the campaigns. Reporting also tied the cluster to campaigns using LNK, HTML, ZIP, and RAR lures, and to activity exploiting or attempting to exploit the WinRAR vulnerability CVE-2025-8088. Malware and tooling directly associated with UAC-0252 in the provided content include SHADOWSNIFF, SALATSTEALER, and DEAFTICK, with a GitHub repository also containing a program with ransomware-like characteristics internally named "AVANGARD ULTIMATE v6.0" and an archive containing an exploit for CVE-2025-8088. Hunt.io reporting states that infrastructure at Beget LLC hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER through CVE-2025-8088. Observed tradecraft includes phishing, impersonation of Ukrainian institutions, abuse of legitimate websites with XSS for payload delivery, use of GitHub for hosting payloads and scripts, archive-based delivery chains, and persistence via a Run key value named WindowsUpdateService pointing to %TMP%\svchost.exe, along with attempts to hide the file and add a Microsoft Defender exclusion. Additional reporting noted overlap between a March 2026 phishing campaign using nested RAR archives and the UAC-0252 cluster, but that attribution was assessed with low confidence. The provided content does not conclusively identify UAC-0252 as a nation-state actor, although the campaigns are Ukraine-focused and use government-themed lures.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Military
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Where they're from
Attributed origin per open-source reporting.
- RU
Tradecraft
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
8 malware families attributed to this actor across reporting.
3 additional families tracked in Mallory.
Associated vulnerabilities
2 CVEs this actor has used in observed campaigns. 2 of them exploited in the wild.
MalwareBazaar pivot analysis ties this sample to a broader campaign cluster exploiting CVE-2025-8088 (WinRAR)... Second, CVE-2025-8088 (a WinRAR vulnerability) appears in three related samples from March 3-10. The password-protected RAR in our sample may be designed to exploit this same vulnerability during extraction. Without the password, we cannot confirm this -- but the pattern is suggestive.
A pivot on the UKR tag in MalwareBazaar reveals a coordinated campaign... 2026-03-05 8150b2b3... RAR UKR, CVE-2025-6218, CVE-2025-8088 Military supply unit; 2026-03-03 ba149847... RAR UKR, UAC-0252, CVE-2025-6218, CVE-2025-8088 Unknown.
Observables
12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Impersonated Ukrainian government institutions and deployed infostealers via exploitation of a WinRAR vulnerability.
Named campaign cluster targeting Ukraine in early 2026, deploying SalatStealer together with SHADOWSNIFF, DEAFTICK, and AVANGARD ULTIMATE v6.0 ransomware. Initial access reportedly used a WinRAR path traversal exploit delivered via Telegram.
A CERT-UA-tracked threat cluster tentatively linked to this phishing campaign through tactical overlap, including Ukrainian government and military-themed lures, related UKR-tagged samples, and possible exploitation of WinRAR vulnerabilities in archive-based delivery chains.
Separate campaign (per CERT-UA) targeting Ukrainian government institutions using information-stealing malware families ShadowSniff and SalatStealer.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.