UAC-0241
- First seen
- 2025-05-01 00:00:00
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- government
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:24:53
Targeted industries: education-and-nonprofits government-and-public-sector
Targeted regions: country_code:ua
Context
UAC-0241 is a threat actor tracked by CERT-UA, active from May to November 2025, targeting educational institutions and government bodies in eastern Ukraine via spear-phishing emails from compromised Gmail accounts. These emails deliver password-protected ZIP archives with malicious LNK files that trigger an HTA → JavaScript → PowerShell chain, deploying credential harvester LaZagne, file-stealer scripts, and the Go-based GAMYBEAR backdoor for command execution, data exfiltration over HTTP, and persistence via registry Run keys. Initial access stemmed from a May 26 phishing spoofing a local emergency agency, with compromised systems exploited for lateral movement.
Reports & references
- CERT-UA — 6286219 (report)