Cyber Serp

Aliases: UAC-0255

Origin
RU
Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 12:26:21

Targeted industries: government-and-public-sector technology-and-telecommunications

Targeted regions: country_code:ua

Context

UAC-0255 is a threat actor that conducted a phishing campaign impersonating CERT-UA to distribute the AGEWHEEZE RAT, targeting organizations in Ukraine's public and private sectors. The campaign is part of a broader trend of using trusted identities to enhance victim engagement, as seen in previous activities like UAC-0190 and UAC-0252. CERT-UA identified UAC-0255 after discovering links to the CyberSerp Telegram channel, which claimed responsibility for the attack. The activity is documented under the identifier CERT-UA#21075, with detection rules available for cybersecurity analysts.

Reports & references

  • socprime.com — Uac 0255 Distributing Agewheeze Rat (report)
  • CERT-UA — 6288047 (report)

External references