UAC-0026 is a cyber-espionage intrusion cluster tracked in relation to the HeaderTip malware campaign targeting Ukrainian organizations. The activity has used conflict-themed phishing lures referencing Russian military crimes in Ukraine and decoy documents themed as official Ukrainian police guidance to induce execution. HeaderTip functions as a backdoor and loader, establishing persistence on Windows systems through Registry Run keys and then downloading and executing additional DLL payloads. Observed tradecraft includes phishing-based initial access, use of decoy documents, staged reconstruction and execution of a DLL payload via a batch script, persistence, obfuscated API resolution, and post-compromise command-and-control over HTTP. Similar activity was reportedly observed as early as September 2020. UAC-0026 has been associated with the malware family HeaderTip, and reporting has linked the cluster to the suspected Chinese threat actor Scarab. The cluster has been observed targeting Ukrainian entities during the Russia-Ukraine war period.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
16 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
33 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A malware campaign leveraging Russia-Ukraine conflict-themed phishing lures to deliver a persistent backdoor/loader. The malware establishes persistence via Registry Run keys, drops DLL and BAT files into %TEMP%, communicates with C2 over HTTP on port 8080 using Dynamic DNS, and can load additional malware such as rootkits or trojans.
Conducting cyber attacks against Ukrainian critical information infrastructure during March 15-22, 2022.
Intrusion activity targeting Ukraine via phishing lures and deployment of the HeaderTip backdoor; assessed to be associated with Scarab.
Conducting social-engineering malware delivery against Ukrainian targets using a RAR archive and decoy PDF related to alleged Russian war crimes evidence, dropping the HeaderTip malware for persistence and follow-on DLL execution.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.