Cyber Serp
Aliases: UAC-0255
- Origin
- RU
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:26:21
Targeted industries: government-and-public-sector technology-and-telecommunications
Targeted regions: country_code:ua
Context
UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting organizations in Ukraine's public and private sectors. The campaign is part of a broader trend of using trusted identities to enhance victim engagement, as seen in previous activities like UAC-0190 and UAC-0252. CERT-UA identified UAC-0255 after discovering links to the CyberSerp Telegram channel, which claimed responsibility for the attack. The activity is documented under the identifier CERT-UA#21075, with detection rules available for cybersecurity analysts.
Reports & references
- socprime.com — Uac 0255 Distributing Agewheeze Rat (report)
- CERT-UA — 6288047 (report)