UAC-0173 is a threat actor group described as targeting Ukrainian organizations. In the provided content, the group is associated with malware campaigns using AsyncRAT, and many UAC-0173 attack samples are stated to be written in .NET. The analyzed AsyncRAT sample attributed to UAC-0173 is a 32-bit Windows executable and is described as using multiple evasion and anti-analysis techniques. Reported behaviors include WMI-based environment and security-product discovery via queries such as SELECT * FROM Win32_CacheMemory and SELECT * FROM AntivirusProduct, process enumeration with CreateToolhelp32Snapshot, termination of security and analysis tools, administrative privilege checks using well-known RIDs including 544, and apparent AMSI bypass activity through tampering with amsi.dll AmsiScanBuffer using base64-encoded strings. The content also lists an associated group identifier, ua_nno_bm. No additional aliases or sub-groups beyond UAC-0173 are directly provided in the content.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
9 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 malware family attributed to this actor across reporting.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced in connection with AsyncRAT and advanced antivirus detection evasion techniques.
Conducting malware campaigns against Ukrainian organizations, with this report focusing on AsyncRAT-based activity and associated antivirus detection evasion, anti-analysis, process killing, privilege checks, and AMSI bypass behavior.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.