UAC-0227

First seen
2025-03-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:23:10

Targeted industries: government-and-public-sector energy-and-utilities

Targeted regions: country_code:fr country_code:de country_code:pl

Context

UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various organizations in the European Union. The group employs phishing campaigns that utilize SVG file attachments to distribute stealers like Amatera Stealer and Strela Stealer. Their tactics include leveraging ClickFix-style methods to implement their threats.

Reports & references

  • cip.gov.ua — Novi Kiberzagrozi Kogo I Yak Atakuyut Vorozhi Ugrupovannya (report)
  • securityaffairs.com — Ukraine Sees Surge In Ai Powered Cyberattacks By Russia Linked Threat Actors (report)

External references