Skip to content

Commit 7e06cf0

Browse files
authored
Merge pull request #1071 from r0ny123/main
Added correct reference link to uac-0226
2 parents f935f60 + 7c814ca commit 7e06cf0

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

clusters/threat-actor.json

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -18158,7 +18158,7 @@
1815818158
"description": "UAC-0226 is a cyber-espionage group targeting Ukrainian military, law enforcement, and local government entities—particularly near the eastern border—since February 2025. Initial access is achieved via phishing emails containing malicious .xlsm documents that decode and execute base64-encoded payloads stored in spreadsheet cells. Two main tools are used: a .NET-based reverse shell leveraging PowerShell code from a public GitHub repository (https://github.com/tihanyin/PSSW100AVB), and GIFTEDCROOK, a C/C++ stealer that extracts browser data (cookies, history, credentials), archives it with PowerShell, and exfiltrates via Telegram. The group often abuses compromised webmail accounts for delivery, underlining the importance of detailed email and web server logging. Their activity shows a mix of low development overhead and high operational targeting, consistent with state-aligned espionage.",
1815918159
"meta": {
1816018160
"refs": [
18161-
"https://cert.gov.ua/article/6282902",
18161+
"https://cert.gov.ua/article/6282946",
1816218162
"https://socprime.com/blog/detect-uac-0226-attacks-against-ukraine/"
1816318163
]
1816418164
},

0 commit comments

Comments
 (0)