UAC-0125 is a Russia-linked cyberespionage threat cluster assessed to have ties to Sandworm, also known as APT44. The actor has targeted Ukrainian military personnel and other Ukraine-related defense entities through phishing and social-engineering operations. Observed activity includes impersonation of trusted software and military-themed services to induce victims to download trojanized installers or backdoor-laced programs. Known operations attributed to UAC-0125 include campaigns using a fake Army+ military application lure against Ukrainian soldiers and email-driven phishing that directed targets to a website masquerading as ESET in order to deliver the C# backdoor Kalambur, also known as SUMBUR, disguised as a threat-removal utility. In these intrusions, the actor abused legitimate cloud and web platforms to host phishing infrastructure and payload delivery components. Reported post-compromise behavior includes concealed access to victim devices, data exfiltration, and follow-on intrusion activity. The cluster is associated with broader Russian cyber operations against Ukraine and aligns with Sandworm-linked targeting of military and defense-related organizations. High-confidence observed tradecraft includes phishing-based initial access, spoofing of legitimate brands or services, malware delivery via trojanized installers, persistence through backdoor deployment, and exfiltration in support of espionage objectives.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
1 indicator attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Cluster targeting Ukrainian military personnel via Cloudflare Workers-hosted delivery, distributing malware disguised as the Army+ app.
Sandworm-linked sub-cluster conducting phishing with spoofed security-vendor (ESET) infrastructure to deliver the Kalambur/SUMBUR C# backdoor.
Cyberespionage activity targeting Ukrainian soldiers via fraudulent Army+ websites that delivered a trojanized installer, enabling device access, data exfiltration, and follow-on attacks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.