UNC5792
Also known as UAC-0195
Reports
7
First seen
Jun 26, 2026
Last seen
Jul 2, 2026
Motivation
Espionage
Relationships
Filled ◆ = CVE exploited in the wild. Entities that appear together in Signalis reporting — co-mention, not confirmed collaboration. Reports naming many actors at once (weekly roundups) are excluded from relationship edges.
Targeting
Sectors
Victim regions
×1×2
United States×2
Ukraine×1
Victim country, only when stated. Corpus is predominantly English-language reporting, so US/EU coverage is overweighted relative to true victim distribution.
Top ATT&CK techniques
T1566 Phishing ×7T1110 Brute Force ×4T1598 Phishing for Information ×4T1078 Valid Accounts ×2T1005 Data from Local System ×2T1056 Input Capture ×2T1187 Forced Authentication ×2T1555 Credentials from Password Stores ×1T1071 Application Layer Protocol ×1T1113 Screen Capture ×1T1567 Exfiltration Over Web Service ×1T1219 Remote Access Software ×1
Indicators
cve ×5domain ×3filename ×1
Indicator values are available on Pro and via the API.
Associated CVEs
Recent reports
High