Russia-Nexus UAC-0113 Emulating Telecommunication Providers in Ukraine
ID: 645198e1-1221-4221-83f0-9d0b1243b7ea
STIX ID: report--645198e1-1221-4221-83f0-9d0b1243b7ea
Threat Score
85/100
Uploaded: 2026-08-14
Published Date: 2022-09-18
Last Modified Date: 2022-09-18
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Recorded Future/Insikt Group documents UAC-0113 (linked by CERT‑UA to Russian GRU/Sandworm) reusing dynamic DNS domains spoofing Ukrainian telecoms to deliver malicious ISO files via HTML smuggling that install Colibri Loader and Warzone RAT; the report provides malware technical analysis, C2/infrastructure and IOC listings, ATT&CK mappings, and mitigations for detection and blocking.
