UAC-0227
- First seen
- 2025-03-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- advanced
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:23:10
Targeted industries: government-and-public-sector energy-and-utilities
Targeted regions: country_code:fr country_code:de country_code:pl
Context
UAC-0227 is an APT group that has been active since at least March 2025, targeting local governments, critical infrastructure, and various organizations in the European Union. The group employs phishing campaigns that utilize SVG file attachments to distribute stealers like Amatera Stealer and Strela Stealer. Their tactics include leveraging ClickFix-style methods to implement their threats.
Reports & references
- cip.gov.ua — Novi Kiberzagrozi Kogo I Yak Atakuyut Vorozhi Ugrupovannya (report)
- securityaffairs.com — Ukraine Sees Surge In Ai Powered Cyberattacks By Russia Linked Threat Actors (report)