Undisclosed government agency in Ukraine.
| Primary URL | Location | Industry | Undetermined |
Country
Ukraine
|
Government - National
|
|---|
Profile
The organisation referenced in the reporting is identified only as an undisclosed government agency whose headquarters is located in Ukraine. As a governmental body, it operates under the authority of the Ukrainian state, although the specific ministry or department to which it reports is not named in any public source. The agency’s official name, mandate, and the particular sector it serves—whether administrative, security, economic, or another function—have not been disclosed. Consequently, no public description of its core responsibilities, the services it provides, or the programmes it manages is available. Because the agency remains unnamed, details such as its organisational structure, internal divisions, or reporting lines are also absent from open‑source material.
In mid‑April 2023, the agency was targeted by a cyber‑espionage operation conducted by the threat actor designated UAC‑0063, which gained initial foothold through a compromised email account belonging to the Embassy of Tajikistan. The attackers used that account to deliver malicious payloads, deploying the LOGPIE keylogger to capture keystrokes and credentials, the CHERRYSPY backdoor to maintain persistent remote access, and the STILLARCH tool to locate and exfiltrate files of interest from the infected network. Throughout the intrusion, the threat actor employed various obfuscation techniques to hinder analysis of the malware and to delay attribution. Researchers noted that UAC‑0063 has shown interest in targets beyond Ukraine, including entities in Israel, India, Kazakhstan, Kyrgyzstan, and Mongolia, indicating a broader intelligence‑gathering focus. The campaign was identified and reported by cybersecurity analysts, who linked the compromise of the diplomatic email address to the initial intrusion vector. No public statement from the agency regarding the breach, its impact, or any remedial actions has been released.
Because the agency’s identity is not publicly disclosed, no concrete information about its workforce size, annual budget, or geographic footprint has been made available through official channels or reputable reporting. Likewise, details concerning its ownership structure—such as which specific ministry or state entity oversees it—are absent from the source material, and there is no mention of any parent organisation or subsidiary units. The absence of such data precludes any statement about its distinguishing attributes, regulatory responsibilities, or sector‑specific competencies beyond the general fact that it is a Ukrainian governmental body. Accordingly, this profile is confined to the verifiable facts of its governmental status in Ukraine and the documented cyber‑espionage incident involving UAC‑0063, without speculation or inference about undisclosed aspects of its operation.
