UAC-0219 is a cyber-espionage group targeting Ukraine's military and government entities with WRECKSTEEL malware for file exfiltration.
Analyst brief
UAC-0219 is an observed cyber-espionage group. They target Ukraine's military innovation hubs, armed forces, law enforcement, and regional government institutions. Their primary TTPs involve file exfiltration using VBScript and PowerShell variants of the WRECKSTEEL malware. Defenders should enhance monitoring for script-based exfiltration and watch for targeted phishing indicators aimed at critical sectors.
UAC-0219
unknown
UAC-0219 is a hacking group observed conducting cyber-espionage operations targeting Ukrainian critical sectors, primarily utilising WRECKSTEEL malware for file exfiltration in both VBScript and PowerShell variants. Their activities focus on gathering intelligence from military innovation hubs, armed forces, law enforcement, and regional government institutions. CERT-UA has linked multiple cyber-attacks against government agencies and critical infrastructure in Ukraine to UAC-0219, emphasizing their reliance on specialized malware for sensitive information theft. The group’s operations are characterized by stealthy access and data exfiltration tactics, consistent with state-sponsored APT behavior.