UAC-0145
Summary
UAC-0145 is a CERT-UA threat cluster targeting Ukraine. CERT-UA describes it as a subcluster of UAC-0002, also known publicly as Sandworm, APT44, and Seashell Blizzard. Those parent-cluster mappings are source assertions; the UAC-0145 label should remain attached to the activity CERT-UA specifically places in this subcluster.
In July 2026, CERT-UA documented the cluster's use of trojanized software, Signal-delivered fake security tools, compromised-site ClickFix pages, Windows malware, and an Android backdoor. The combination supports access, reconnaissance, credential/data theft, remote control, and potential preparation for destructive follow-on operations.
Tags
- actor
- group
- UAC-0145
- UAC-0002
- Sandworm
- APT44
- Seashell Blizzard
- Russia
- GRU
- Ukraine
- espionage
- destructive operations
- ClickFix
- Android
- Signal
- compromised websites
- EtherHiding
Attribution and confidence
- CERT-UA explicitly calls UAC-0145 a subcluster of UAC-0002 / Sandworm / APT44 / Seashell Blizzard.
- The parent cluster is publicly associated with Russia's military intelligence service. Keep this relationship source-bound and do not automatically assign unrelated ClickFix or Android activity to UAC-0145.
- Shared use of fake CAPTCHAs, Ethereum dead drops, Dropbox, Steam Community, Tor, or OpenSSH is insufficient attribution; these are widely available techniques and services.
Observed access patterns
- Backdoored Windows and Microsoft Office installers distributed through torrent trackers.
- Fake antivirus/security tooling delivered through Signal after direct interaction with targets, including Ukrainian military personnel.
- Compromised websites serving selectively displayed ClickFix CAPTCHAs.
- Android APKs masquerading as security software and delivered through messaging applications.
Tooling
CERT-UA associates the cluster with:
- KALAMBUR, SUMBUR, and TAMBUR
- GHETTOVIBE Startup-folder VBS payload
- SCOUTCURL PowerShell reconnaissance
- FLUIDLEECH and LOADLOOP loaders
- FREAKYPOLL Python backdoor
- SMARTAXE compromised-page injection and smart-contract domain resolution
- COWARDDUCK Android backdoor
- OpenSSH and Tor port forwarding, plus RSYNC for exfiltration in earlier activity
Defender priorities
- Scope detections around the complete delivery chain rather than malware names alone: messenger or browser lure → user-run PowerShell/APK → persistence or reconnaissance → cloud/legitimate-service C2 and exfiltration.
- Treat compromised websites and mobile devices as first-class evidence sources, not merely delivery infrastructure.
- Separate confidence levels: a match on CERT-UA's published hashes or infrastructure supports campaign linkage; a generic ClickFix event does not.
- If UAC-0145 presence is confirmed, investigate lateral movement and destructive preparation because CERT-UA links a prior torrent-delivered compromise to a later destructive government-network attack.
Related pages
- UAC-0145 ClickFix, SMARTAXE, and COWARDDUCK campaign
- APT28 LNK SmartScreen bypass and CVE-2026-32202 coercion chain
- Gamaredon