The Russia-linked advanced persistent threat group UAC-0184, also known as Hive0156, has intensified its espionage operations against Ukrainian military and government entities by leveraging the Viber messaging platform as an initial attack vector. The group distributed malicious ZIP archives disguised as official documents, which contained Windows shortcut (LNK) files masquerading as Microsoft Word, Excel, and other document types. When opened, these LNK files executed a multi-stage infection chain, including the deployment of the Hijack Loader malware, which facilitated further compromise through techniques such as DLL side-loading, module stomping, and in-memory execution to evade detection. The phishing lures exploited sensitive themes, such as military personnel record changes and compensation issues, to increase the likelihood of successful compromise.
The attack chain involved the use of PowerShell scripts to download additional payloads, with the malware designed to scan for and evade common security software. Persistence was established via scheduled tasks, and the campaign was observed to target high-value Ukrainian government bodies, including the Verkhovna Rada. Security researchers recommend strengthening security awareness, encryption, and access controls to mitigate the risk from such sophisticated phishing and malware delivery tactics. The campaign is expected to continue, with UAC-0184 evolving its methods and maintaining a focus on intelligence gathering against Ukrainian targets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-01-05, multiple security outlets reported that UAC-0184 had been abusing Viber in 2025 to spy on Ukrainian military and government targets. The reporting tied the activity to the group's known toolchain and highlighted its shift from other messaging platforms such as Signal and Telegram.
In the 2025 campaign, opening the ZIP files triggered a multi-stage infection chain using LNK files, PowerShell, and side-loading techniques to install Hijack Loader and then Remcos RAT. The malware provided remote access, persistence, security-tool reconnaissance, and data theft capabilities while using evasion methods such as in-memory execution and module stomping.
During 2025, the Russia-aligned threat actor UAC-0184, also known as Hive0156, targeted Ukrainian military and government organizations, including the Verkhovna Rada, by sending malicious ZIP archives through Viber. The messages used official-document and military-themed lures to trick recipients into opening weaponized files.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
rescana.com
Open sourcethehackernews.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.