UAC-0020

Aliases: Vermin, SickSync

First seen
2018-01-01 00:00:00
Origin
RU
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:15:58

Targeted industries: government-and-public-sector defense-and-aerospace

Targeted regions: country_code:ua

Context

Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin. They have targeted Ukrainian government infrastructure using malware like Spectr and legitimate tools like SyncThing for data exfiltration. Vermin has been active since at least 2018, using custom-made RATs like Vermin and open-source tools like Quasar for cyber-espionage. The group has resurfaced after periods of inactivity to conduct espionage operations against Ukraine's military and defense sectors.

Reports & references

  • cloud.google.com — Updated Cyber Threat Actor Naming System (report)
  • socprime.com — Vermin Uac 0020 Hacking Collective Hits Ukrainian Government And Military With Spectr Malware (report)
  • therecord.media — Russian Vermin Hackers Target Ukraine (report)
  • CERT-UA — 6279600 (report)

External references