Skip to main content
Mallory
🇷🇺 RU8 malware familiesExploits CVEs in the wild

UAC-0252

Also known asUAC-0252

UAC-0252 is a threat cluster tracked by CERT-UA and associated in CERT-UA reporting with individuals discussed on the Telegram channel "PalachPro." The activity targets Ukraine, including Ukrainian government institutions, central executive authorities, and regional administrations, and uses phishing emails impersonating Ukrainian government bodies and regional administrations. Lures have included themes related to updating widely used civilian and military mobile applications and documents impersonating Ukrainian government institutions, including the Bureau of Economic Security of Ukraine. CERT-UA reported repeated campaigns beginning in January 2026. Delivery methods included attached archives containing EXE payloads and links to legitimate but XSS-vulnerable websites that executed JavaScript and downloaded executables. GitHub-hosted payloads and scripts were used in the campaigns. Reporting also tied the cluster to campaigns using LNK, HTML, ZIP, and RAR lures, and to activity exploiting or attempting to exploit the WinRAR vulnerability CVE-2025-8088. Malware and tooling directly associated with UAC-0252 in the provided content include SHADOWSNIFF, SALATSTEALER, and DEAFTICK, with a GitHub repository also containing a program with ransomware-like characteristics internally named "AVANGARD ULTIMATE v6.0" and an archive containing an exploit for CVE-2025-8088. Hunt.io reporting states that infrastructure at Beget LLC hosted activity tied to the UAC-0252 campaign, which impersonated Ukrainian government institutions and deployed SHADOWSNIFF and SALATSTEALER through CVE-2025-8088. Observed tradecraft includes phishing, impersonation of Ukrainian institutions, abuse of legitimate websites with XSS for payload delivery, use of GitHub for hosting payloads and scripts, archive-based delivery chains, and persistence via a Run key value named WindowsUpdateService pointing to %TMP%\svchost.exe, along with attempts to hide the file and add a Microsoft Defender exclusion. Additional reporting noted overlap between a March 2026 phishing campaign using nested RAR archives and the UAC-0252 cluster, but that attribution was assessed with low confidence. The provided content does not conclusively identify UAC-0252 as a nation-state actor, although the campaigns are Ukraine-focused and use government-themed lures.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Who they target

Sectors the actor has been observed targeting.

  • Government & Administration
  • Military

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine

Where they're from

Attributed origin per open-source reporting.

  • RU
MITRE ATT&CK

Tradecraft

11 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics16 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
1 technique
T1566×3
Phishing
T1566.001×3
Spearphishing Attachment
T1566.002×2
Spearphishing Link
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1203×3
Exploitation for Client Execution
TA0003
Persistence
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
1 technique
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
2 techniques
T1036
Masquerading
T1564
Hide Artifacts
T1564.001
Hidden Files and Directories
TA0011
Command and Control
2 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105
Ingress Tool Transfer
IOCS

Observables

12 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping11

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal8

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs2

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables12

Domains, IPs, and hashes tied to this actor, refreshed continuously.