UAC-0239 targets Ukrainian entities via spearphishing, impersonating state agencies and using OrcaC2 and FILEMESS.
Analyst brief
UAC-0239 is a threat actor targeting Ukrainian Defence Forces and state agencies, impersonating the Security Service of Ukraine. They conduct spearphishing attacks themed around "countering russian sabotage-reconnaissance groups" to disguise malicious intent. The group leverages the OrcaC2 framework and FILEMESS stealer as part of their TTPs. Defenders should scrutinize emails impersonating government entities and monitor for OrcaC2 traffic and FILEMESS stealer activity.
UAC-0239
unknown
UAC-0239 has been observed conducting spearphishing attacks targeting the Defence Forces and local state agencies of Ukraine, impersonating the Security Service of Ukraine. The group employs the OrcaC2 framework and FILEMESS stealer to compromise these organizations. Their campaigns often utilize themes related to "countering russian sabotage-reconnaissance groups" to disguise their malicious intent.