UAC-0226 is a cyber-espionage group targeting Ukrainian entities near the eastern border since February 2025.
Analyst brief
UAC-0226 is a cyber-espionage group active since February 2025, targeting Ukrainian military, law enforcement, and local government entities near the eastern border. Initial access relies on phishing emails with malicious .xlsm documents; they deploy a .NET-based reverse shell using PowerShell code from a public GitHub repository, and the GIFTEDCROOK stealer to collect browser data (cookies, history, credentials) and exfiltrate it via Telegram. Defenders should improve detections for suspicious .xlsm attachments, unusual PowerShell execution, and network requests to Telegram API, while remaining vigilant for internal phishing threats from compromised webmail accounts.
UAC-0226
unknown
UAC-0226 is a cyber-espionage group targeting Ukrainian military, law enforcement, and local government entities—particularly near the eastern border—since February 2025. Initial access is achieved via phishing emails containing malicious .xlsm documents that decode and execute base64-encoded payloads stored in spreadsheet cells. Two main tools are used: a .NET-based reverse shell leveraging PowerShell code from a public GitHub repository (https://github.com/tihanyin/PSSW100AVB), and GIFTEDCROOK, a C/C++ stealer that extracts browser data (cookies, history, credentials), archives it with PowerShell, and exfiltrates via Telegram. The group often abuses compromised webmail accounts for delivery, underlining the importance of detailed email and web server logging. Their activity shows a mix of low development overhead and high operational targeting, consistent with state-aligned espionage.