logo

Russia-Nexus UAC-0113 Emulating Telecommunication Providers in Ukraine

ID: 645198e1-1221-4221-83f0-9d0b1243b7ea

STIX ID: report--645198e1-1221-4221-83f0-9d0b1243b7ea

Threat Score

85/100

Uploaded: 2026-08-14

Published Date: 2022-09-18

Last Modified Date: 2022-09-18

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future/Insikt Group documents UAC-0113 (linked by CERT‑UA to Russian GRU/Sandworm) reusing dynamic DNS domains spoofing Ukrainian telecoms to deliver malicious ISO files via HTML smuggling that install Colibri Loader and Warzone RAT; the report provides malware technical analysis, C2/infrastructure and IOC listings, ATT&CK mappings, and mitigations for detection and blocking.