Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
state-sponsored-espionagephishing-campaign-intelligencegovernment-diplomatic-threatloader-delivery-mechanism

Russia-Aligned UAC-0184 Targets Ukrainian Military via Viber Phishing Campaign

Updated 3mo agoFirst seen Jan 6, 20263 sources

The Russia-linked advanced persistent threat group UAC-0184, also known as Hive0156, has intensified its espionage operations against Ukrainian military and government entities by leveraging the Viber messaging platform as an initial attack vector. The group distributed malicious ZIP archives disguised as official documents, which contained Windows shortcut (LNK) files masquerading as Microsoft Word, Excel, and other document types. When opened, these LNK files executed a multi-stage infection chain, including the deployment of the Hijack Loader malware, which facilitated further compromise through techniques such as DLL side-loading, module stomping, and in-memory execution to evade detection. The phishing lures exploited sensitive themes, such as military personnel record changes and compensation issues, to increase the likelihood of successful compromise.

The attack chain involved the use of PowerShell scripts to download additional payloads, with the malware designed to scan for and evade common security software. Persistence was established via scheduled tasks, and the campaign was observed to target high-value Ukrainian government bodies, including the Verkhovna Rada. Security researchers recommend strengthening security awareness, encryption, and access controls to mitigate the risk from such sophisticated phishing and malware delivery tactics. The campaign is expected to continue, with UAC-0184 evolving its methods and maintaining a focus on intelligence gathering against Ukrainian targets.

Share:
Russia-Aligned UAC-0184 Targets Ukrainian Military via Viber Phishing Campaign
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jan 5, 20266mo ago

Researchers publicly document UAC-0184's Viber-based espionage campaign

On 2026-01-05, multiple security outlets reported that UAC-0184 had been abusing Viber in 2025 to spy on Ukrainian military and government targets. The reporting tied the activity to the group's known toolchain and highlighted its shift from other messaging platforms such as Signal and Telegram.

Jan 1, 20251y ago

Attack chain deploys Hijack Loader and Remcos RAT on victim systems

In the 2025 campaign, opening the ZIP files triggered a multi-stage infection chain using LNK files, PowerShell, and side-loading techniques to install Hijack Loader and then Remcos RAT. The malware provided remote access, persistence, security-tool reconnaissance, and data theft capabilities while using evasion methods such as in-memory execution and module stomping.

UAC-0184 conducts Viber spearphishing against Ukrainian entities in 2025

During 2025, the Russia-aligned threat actor UAC-0184, also known as Hive0156, targeted Ukrainian military and government organizations, including the Verkhovna Rada, by sending malicious ZIP archives through Viber. The messages used official-document and military-themed lures to trick recipients into opening weaponized files.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

18 LINKEDOpen in app
Threat actors
1 linked
Affected products
5 linked
ViberWindowsPowershellTelegramSignal
Organizations
9 linked
RescanaEmsisoftKasperskyAvastMicrosoft CorporationBitdefenderWebrootViber360 Advanced Threat Research Institute
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.