UAC-0149

Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:15:10

Targeted industries: defense-and-aerospace

Targeted regions: country_code:ua

Context

UAC-0149 is a threat actor targeting the Armed Forces of Ukraine with COOKBOX malware. They use obfuscation techniques like character encoding and base64 encoding to evade detection. The group leverages dynamic DNS services and Cloudflare Workers for their C2 infrastructure.

Reports & references

  • socprime.com — Uac 0149 Attack Detection Hackers Launch A Targeted Attack Against The Armed Forces Of Ukraine As Cert Ua Reports (report)
  • CERT-UA — 6277849 (report)

External references