UAC-0099
Reports
3
First seen
Dec 2, 2025
Last seen
Jul 24, 2026
Motivation
Espionage, Sabotage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×2×2
Ukraine×2
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×3T1547 Boot or Logon Autostart Execution ×2T1027 Obfuscated Files or Information ×2T1204 User Execution ×2T1053 Scheduled Task/Job ×2T1041 Exfiltration Over C2 Channel ×2T1005 Data from Local System ×2T1218 System Binary Proxy Execution ×2T1190 Exploit Public-Facing Application ×1T1219 Remote Access Software ×1T1486 Data Encrypted for Impact ×1T1498 Network Denial of Service ×1
Indicators
cve ×8filename ×7domain ×2
Indicator values are available on Pro and via the API.