Skip to content

UAC-0145

Summary

UAC-0145 is a CERT-UA threat cluster targeting Ukraine. CERT-UA describes it as a subcluster of UAC-0002, also known publicly as Sandworm, APT44, and Seashell Blizzard. Those parent-cluster mappings are source assertions; the UAC-0145 label should remain attached to the activity CERT-UA specifically places in this subcluster.

In July 2026, CERT-UA documented the cluster's use of trojanized software, Signal-delivered fake security tools, compromised-site ClickFix pages, Windows malware, and an Android backdoor. The combination supports access, reconnaissance, credential/data theft, remote control, and potential preparation for destructive follow-on operations.

Tags

Attribution and confidence

  • CERT-UA explicitly calls UAC-0145 a subcluster of UAC-0002 / Sandworm / APT44 / Seashell Blizzard.
  • The parent cluster is publicly associated with Russia's military intelligence service. Keep this relationship source-bound and do not automatically assign unrelated ClickFix or Android activity to UAC-0145.
  • Shared use of fake CAPTCHAs, Ethereum dead drops, Dropbox, Steam Community, Tor, or OpenSSH is insufficient attribution; these are widely available techniques and services.

Observed access patterns

  • Backdoored Windows and Microsoft Office installers distributed through torrent trackers.
  • Fake antivirus/security tooling delivered through Signal after direct interaction with targets, including Ukrainian military personnel.
  • Compromised websites serving selectively displayed ClickFix CAPTCHAs.
  • Android APKs masquerading as security software and delivered through messaging applications.

Tooling

CERT-UA associates the cluster with:

  • KALAMBUR, SUMBUR, and TAMBUR
  • GHETTOVIBE Startup-folder VBS payload
  • SCOUTCURL PowerShell reconnaissance
  • FLUIDLEECH and LOADLOOP loaders
  • FREAKYPOLL Python backdoor
  • SMARTAXE compromised-page injection and smart-contract domain resolution
  • COWARDDUCK Android backdoor
  • OpenSSH and Tor port forwarding, plus RSYNC for exfiltration in earlier activity

Defender priorities

  • Scope detections around the complete delivery chain rather than malware names alone: messenger or browser lure → user-run PowerShell/APK → persistence or reconnaissance → cloud/legitimate-service C2 and exfiltration.
  • Treat compromised websites and mobile devices as first-class evidence sources, not merely delivery infrastructure.
  • Separate confidence levels: a match on CERT-UA's published hashes or infrastructure supports campaign linkage; a generic ClickFix event does not.
  • If UAC-0145 presence is confirmed, investigate lateral movement and destructive preparation because CERT-UA links a prior torrent-delivered compromise to a later destructive government-network attack.

Sources