UAC-0247
UAC-0247 is a threat cluster tracked by CERT-UA, previously tracked as UAC-0244. CERT-UA reported active campaigns by this cluster since early 2026, with activity observed during March and April 2026. The actor has targeted Ukraine, including local governments, municipal authorities, government entities, municipal healthcare institutions, clinical hospitals, emergency medical services, emergency hospitals, representatives of Ukraine’s Defense Forces, and FPV drone operators. CERT-UA stated that the origin of UAC-0247 remains unclear. The cluster has used phishing emails themed around humanitarian aid proposals or offers, as well as trojanized software delivery, to lure victims. In reported campaigns, links in phishing messages redirected victims to compromised legitimate websites, websites with embedded malicious scripts, or AI-generated fake websites, which then delivered archives containing malicious LNK files or ZIP archives. Execution chains included LNK-triggered HTA execution via mshta.exe, decoy HTA forms, scheduled-task persistence, EXE payloads that injected shellcode into legitimate processes such as RuntimeBroker.exe, DLL side-loading, and in some cases a backdoor capable of establishing a reverse shell to attacker-controlled infrastructure. CERT-UA also reported Signal-delivered archives masquerading as updated FPV drone operator software such as “BACHU.” UAC-0247 has been associated with malware and tooling including AGINGFLY, SILENTLOOP, RAVENSHELL, CHROMELEVATOR, ZAPIXDESK, SilentLoop, ChromeElevator, ZapixDesk, and in one case XMRIG. AGINGFLY is described as a C# remote access tool or backdoor that supports remote command execution, file download, screenshot capture, keylogging, arbitrary code execution, and theft of data from Chromium-based browsers and WhatsApp for Windows. CERT-UA reported that AGINGFLY communicates over WebSockets, encrypts traffic with AES-CBC using a static key, and dynamically retrieves command handlers from its C2 server as source code and compiles them at runtime. SILENTLOOP is a PowerShell persistence script that can execute commands, update configuration, and retrieve current C2 information from Telegram. RAVENSHELL or a TCP reverse shell has been used as a stager. The actor also used CHROMELEVATOR to steal browser credentials and other sensitive browser data, ZAPIXDESK to extract WhatsApp data, RustScan and basic subnet scanners for reconnaissance, and LIGOLO-NG and CHISEL for covert tunneling. CERT-UA reported that the cluster’s operations were primarily espionage-focused, involving theft of sensitive data, credential theft, reconnaissance, and lateral movement inside victim networks. In at least one case, compromised systems were also used for cryptocurrency mining via XMRIG.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Who they target
Sectors the actor has been observed targeting.
- Government & Administration
- Health Care Equipment & Services
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Tradecraft
42 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
12 malware families attributed to this actor across reporting.
7 additional families tracked in Mallory.
Observables
296 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
9 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Threat activity cluster targeting Ukrainian drone operators with ZIP-delivered HTA droppers and a backdoor that establishes a reverse shell.
Espionage campaign targeting Ukrainian hospitals, municipal authorities, and emergency medical services, attempting to steal sensitive data and in some cases use compromised systems for cryptocurrency mining.
Conducting phishing-based malware campaigns in Ukraine targeting local governments and healthcare providers, using humanitarian assistance lures to deliver AgingFly for data theft.
Conducting phishing-led intrusions against Ukrainian local government, municipal healthcare, Defense Forces representatives, and FPV drone operators to steal browser and WhatsApp data, perform network reconnaissance, establish persistence and tunneling, and maintain remote access.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.