UAC-0241 is a spear-phishing threat actor targeting educational and government entities in eastern Ukraine.
Analyst brief
UAC-0241 is a threat actor tracked by CERT-UA, active from May to November 2025. It primarily targets educational institutions and government bodies in eastern Ukraine. The actor uses spear-phishing emails from compromised Gmail accounts delivering password-protected ZIP archives; malicious LNK files trigger an HTA → JavaScript → PowerShell chain to deploy the LaZagne credential harvester, file-stealer scripts, and the GAMYBEAR backdoor. Defenders should focus on password-protected archives from suspicious Gmail accounts, unusual LNK execution, and persistence mechanisms via registry Run keys.
UAC-0241
unknown
UAC-0241 is a threat actor tracked by CERT-UA, active from May to November 2025, targeting educational institutions and government bodies in eastern Ukraine via spear-phishing emails from compromised Gmail accounts. These emails deliver password-protected ZIP archives with malicious LNK files that trigger an HTA → JavaScript → PowerShell chain, deploying credential harvester LaZagne, file-stealer scripts, and the Go-based GAMYBEAR backdoor for command execution, data exfiltration over HTTP, and persistence via registry Run keys. Initial access stemmed from a May 26 phishing spoofing a local emergency agency, with compromised systems exploited for lateral movement.