logo

UAC-0252 Attack Detection: SHADOWSNIFF and SALATSTEALER Fuel Phishing Campaigns in Ukraine

ID: 1b1241fc-604d-59aa-be61-63949b771cc1

STIX ID: report--1b1241fc-604d-59aa-be61-63949b771cc1

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-03-03

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

CERT-UA has tracked UAC-0252 phishing campaigns targeting Ukrainian entities since January 2026 that use well-crafted lures to deliver EXE payloads (via attached archives or XSS on legitimate sites) hosted on GitHub; observed tooling includes SHADOWSNIFF, the SALATSTEALER infostealer, the DEAFTICK backdoor, a discovered ransomware encryptor labeled AVANGARD ULTIMATE v6.0, and use of a WinRAR exploit (CVE-2025-8088), with attribution ties to actors discussed on the PalachPro Telegram channel.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.