Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
MalwareUsed by 1 actor

OrcaC2

OrcaC2 is a multifunction, Go-based command-and-control framework whose source code is publicly available on GitHub. In the provided reporting, CERT-UA described OrcaC2 as an open-source C2 framework used by threat actor UAC-0239 in spearphishing campaigns targeting Ukraine’s Defence Forces, local government bodies, and, more broadly, Ukrainian institutions. Observed delivery involved phishing emails sent via services such as Ukr.net and Gmail, impersonating trusted Ukrainian entities and distributing password-protected archives or VHD files containing an executable and decoy documents. OrcaC2 was also reported as being dropped alongside the FILEMESS stealer.

Reported OrcaC2 capabilities include remote command execution, an interactive shell, system manipulation, file transfer, screenshots, keylogging, process control including memory dumps, UAC bypass, shellcode execution, multiple process-injection techniques, proxy support, SOCKS, SSH and SMB traffic tunneling, port scanning, and password brute-forcing. Reported persistence mechanisms observed or possible for OrcaC2 include scheduled tasks, Run registry entries, and services.

High-confidence association in the content links OrcaC2 to UAC-0239 activity against Ukrainian defense forces and local/state government agencies, including campaigns themed around “countering russian sabotage-reconnaissance groups.” No OrcaC2-specific file hashes, domains, IPs, or other unique indicators were provided in the content.

Share:
For your environment

Hunt this family in your stack

Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.

THREAT ACTORS

Groups observed using it

1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.

View more details
UAC-0239

"Adversaries employ OrcaC2, a multifunction Go-based C2 framework whose source code is publicly available on GitHub..."

via socprime blogsocprime.com
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets match these IOCs, which detections are missing, which campaigns to expect next, and what to do in the next 30 minutes.
IOC matching

Match every observed IP, domain, and hash against your live telemetry.

Threat actor attribution1

Named campaigns wielding this family, with evidence pinned to each claim.

Exploited vulnerabilities

CVEs this family uses for access and lateral movement.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

MITRE ATT&CK mapping

Every documented technique, ranked by evidence weight.

Researcher chatter

Reddit, Mastodon, and CTI community discussion around this family.