UAPS is a cybercriminal actor associated with the creation, distribution, and deployment of the Meduza infostealer. Russian authorities publicly linked members of this actor to development activity spanning roughly two years and additionally alleged involvement in a separate malware strain designed to disable security tooling and support botnet formation for large-scale attacks. Meduza is a credential- and data-theft malware family with broad collection capabilities against browser-stored information, password managers, cryptocurrency wallets, messaging applications, email clients, VPN software, and host profiling data. Based on the reported functionality attributed to Meduza and the related malware, UAPS demonstrates capabilities in credential theft, session hijacking through cookie theft, crypto-theft, exfiltration, defense evasion, and botnet-enabling post-compromise activity. Available information supports classification as a financially motivated cybercrime actor rather than a state-sponsored espionage group. No corroborated aliases or sub-groups beyond the name UAPS are established in the supplied facts.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Geographies tied to known operations.
Attributed origin per open-source reporting.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.