UAC-0056
Attribution profile
STIX characteristics
Threat actor characteristics are available to members.
Profile narrative
The threat actor tracked under the aliases Ember Bear, UAC-0056, SaintBear, UNC2589, Lorec53 and TA471 has been observed operating from Ukraine and is described by Ukrainian authorities as a Russian state‑backed group whose activities align with Russian state interests. It has been active since at least March 2021 and primarily targets Ukrainian government bodies, including central and local authorities, state organizations and private media outlets such as the ICTV television channel, while also being observed phishing Georgian government agencies. The group’s operators are additionally suspected of conducting operations against entities in North America and Western Europe. Its strategic objectives involve espionage through the deployment of backdoors and information stealers, disruption via wiper malware, and the use of fake ransomware to conceal its activities. No financial gain motive is explicitly stated in the available reporting. Attribution to Russian state hackers is repeatedly cited in Ukrainian cyber‑security advisories and threat‑intelligence analyses.
Initial access is most commonly achieved through spear‑phishing emails that contain malicious macro‑enabled Excel documents or other weaponized attachments, a technique seen in the March 2022 campaign that dropped an Elephant dropper written in Go and signed with a stolen Microsoft certificate. The actor frequently implants a web shell, first observed in December 2021, which subsequently serves as a launchpad for additional malware such as the CredPump, HoaxPen and HoaxApe backdoors, often deployed with the assistance of tunneling tools like GOST and Ngrok. Post‑exploitation tooling includes the GrimPlant and GraphSteel implants (also known as the Elephant implant and client), Cobalt Strike Beacon, and a suite of Go‑language droppers, downloaders and clients that establish persistence via auto‑run registry keys, communicate over gRPC with TLS‑protected channels, retrieve machine identifiers via the MachineID library and ipify.org, and encrypt C2 configuration with AES. Notable operations attributed to the group include the WhisperGate wiper attack against Ukrainian government systems in early 2022, the macro‑embedded Excel phishing wave targeting ICTV and other Ukrainian entities in March 2022, and the earlier December 2021 web‑shell campaign that facilitated the February 2022 deployment of CredPump‑family backdoors. The actor has also been linked to fake translation software lures and repeated phishing attempts against Georgian government agencies, demonstrating a pattern of using socially engineered documents to gain footholds in target networks.
Incidents
Attributed incidents are available to members.
0 incidents