# UAC-0247

> As of 2026-05-30, UAC-0247 is a Russia-nexus threat actor tracked by Threadlinqs Intelligence across 3 threats spanning malware. Also known as AgingFly operators. ATT&CK coverage spans 58 techniques across 14 tactics in 3 of 3 tracked threats. Most-observed techniques: T1027 (Obfuscated Files or Information), T1041 (Exfiltration Over C2 Channel), T1059 (Command and Scripting Interpreter).

- **Nation:** Russia
- **Tracked threats:** 3
- **Categories:** MALWARE
- **Also known as:** AgingFly operators
- **As of:** 2026-05-30

## ATT&CK techniques observed

58 techniques observed across 3 of 3 tracked threats. Tactics: Command and Control (8), Stealth (formerly Defense Evasion) (8), Execution (7), Credential Access (6), Discovery (6), Resource Development (6).

- [T1027](https://intel.threadlinqs.com/technique/T1027) Obfuscated Files or Information — Stealth (formerly Defense Evasion) — observed in 3 of 3 tracked threats
- [T1041](https://intel.threadlinqs.com/technique/T1041) Exfiltration Over C2 Channel — Exfiltration — observed in 3 of 3 tracked threats
- [T1059](https://intel.threadlinqs.com/technique/T1059) Command and Scripting Interpreter — Execution — observed in 3 of 3 tracked threats
- [T1082](https://intel.threadlinqs.com/technique/T1082) System Information Discovery — Discovery — observed in 3 of 3 tracked threats
- [T1113](https://intel.threadlinqs.com/technique/T1113) Screen Capture — Collection — observed in 3 of 3 tracked threats
- [T1204](https://intel.threadlinqs.com/technique/T1204) User Execution — Execution — observed in 3 of 3 tracked threats
- [T1555](https://intel.threadlinqs.com/technique/T1555) Credentials from Password Stores — Credential Access — observed in 3 of 3 tracked threats
- [T1566](https://intel.threadlinqs.com/technique/T1566) Phishing — Initial Access — observed in 3 of 3 tracked threats
- [T1573](https://intel.threadlinqs.com/technique/T1573) Encrypted Channel — Command and Control — observed in 3 of 3 tracked threats
- [T1005](https://intel.threadlinqs.com/technique/T1005) Data from Local System — Collection — observed in 2 of 3 tracked threats
- [T1036](https://intel.threadlinqs.com/technique/T1036) Masquerading — Stealth (formerly Defense Evasion) — observed in 2 of 3 tracked threats
- [T1046](https://intel.threadlinqs.com/technique/T1046) Network Service Discovery — Discovery — observed in 2 of 3 tracked threats
- [T1053](https://intel.threadlinqs.com/technique/T1053) Scheduled Task/Job — Persistence — observed in 2 of 3 tracked threats
- [T1055](https://intel.threadlinqs.com/technique/T1055) Process Injection — Privilege Escalation — observed in 2 of 3 tracked threats
- [T1071](https://intel.threadlinqs.com/technique/T1071) Application Layer Protocol — Command and Control — observed in 2 of 3 tracked threats

## Tracked threats

- [AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnel](https://intel.threadlinqs.com/threat/TL-2026-0389) — HIGH
- [UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian Hospitals, Local Government, and FPV Drone Operators](https://intel.threadlinqs.com/threat/TL-2026-0377) — HIGH
- [AgingFly Malware — UAC-0247 Targets Ukrainian Government Agencies and Hospitals with Novel Dynamic C2 RAT](https://intel.threadlinqs.com/threat/TL-2026-0372) — HIGH

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/UAC-0247
