SaintBear__2022__Sentinelone_UAC-0056-Targeting-Ukraine-Fake-Translation-Software_03-15-2022.pdf
ID: 94d6b425-814f-4f3e-9731-4929ce2c1801
STIX ID: report--94d6b425-814f-4f3e-9731-4929ce2c1801
Threat Score
78/100
Uploaded: 2026-08-19
Published Date: 2022-03-22
Last Modified Date: 2022-03-22
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
SentinelOne reports that UAC-0056 (aka UNC2589/TA471) targeted Ukraine using a Python-compiled dictionary-translator that drops Go binaries and the GrimPlant and GraphSteel malware, establishes persistence, harvests credentials, and connects to a Go-downloader C2 server, with multiple file paths and IOCs documented.
