A cyber espionage actor linked to Russia's APT28, targeting government entities in Ukraine and Central Asia.
Analyst brief
UAC-0063 is a cyber espionage actor linked to the Russian APT28 group. It primarily targets government entities in Ukraine, Central Asia (Mongolia, Kazakhstan, Kyrgyzstan), Israel, and India. Its key TTPs include spear-phishing campaigns, deploying malware such as Hatvibe and Cherryspy, using keyloggers and backdoors, and exploiting vulnerabilities in software like HFS HTTP File Server. Defenders should focus on email security filtering, monitoring for anomalies related to file-sharing server exploitation, and hunting for known UAC-0063 indicators of compromise.
UAC-0063
unknown
UAC-0063 is a threat actor linked to Russian APT28, known for targeting government entities in Ukraine and Central Asia for cyber espionage operations. They utilize keyloggers, backdoors, and malware like Hatvibe and Cherryspy to compromise systems and exfiltrate sensitive information. The group has been active since at least 2021 and has shown interest in targeting organizations in Mongolia, Kazakhstan, Kyrgyzstan, Israel, and India. Their TTPs include spear-phishing campaigns and exploiting vulnerabilities in software products like HFS HTTP File Server and Rejetto file-sharing servers.