APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs) — Threadlinqs Intelligence
As of 2026-05-30, APT28/UAC-0001 Sustained Cyber Espionage Against Ukraine & EU (2024-2026 New TTPs) is a high-severity apt threat attributed to APT28 (Russia (GRU — Main Intelligence Directorate, 85th GTsSS, Military Unit 26165)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 46 indicators of compromise.
Threat ID: TL-2026-0066 · Severity: HIGH · Status: ACTIVE · Category: APT
Attribution: APT28 · Russia (GRU — Main Intelligence Directorate, 85th GTsSS, Military Unit 26165) · ESPIONAGE
APT28 (Fancy Bear / UAC-0001 / Forest Blizzard / BlueDelta / GRU Unit 26165) has executed a sustained, multi-vector cyber espionage campaign against Ukraine and EU member states throughout 2024-2026,
APT28/UAC-0001 Sustained Cyber Espionage Campaign Against Ukraine and EU (2024-2026 New TTPs)
Attribution: GRU 85th Main Special Service Center (GTsSS), Military Unit 26165. Tracked as APT28, Fancy Bear, Forest Blizzard, BlueDelta, Sednit, Sofacy, Pawn Storm, STRONTIUM, ITG05, UAC-0001, UAC-0028, and 20+ other aliases.
This threat consolidates the significant escalation in APT28's capabilities and targeting during the 2024-2026 period, focusing on newly documented TTPs that represent evolution beyond previously tracked activity (see TL-2026-0052 for earlier APT28 operations).
=== CAMPAIGN 1: OPERATION PHANTOM NET VOXEL (Sekoia, Sep 2025) ===
Infection Vector: Signal Desktop spearphishing — a first for APT28. Signal Desktop does NOT implement Mark of the Web (MOTW), meaning files received via Signal do not get tagged with the ADS zone identifier. This allows VBA macros in received Office documents to execute without Microsoft Office's MOTW-based security blocks (which would normally prevent macro execution for internet-downloaded files).
Social Engineering: Messages sent via private Signal chats, impersonating colleagues/superiors, invoking compensation decisions and threatening legal action to create urgency. Targets: Ukrainian military administrative staff — brigade-level HR, logistics, command structures.
Lure Documents: Ukrainian military administrative forms — personnel evaluations, medical compensation requests, drone delivery receipts, military permission forms. At least 11 weaponized Office documents identified. Documents designed to appear credible to on-the-ground military personnel under martial law.
Infection Chain:
1. VBA macros in Office document execute on open (no MOTW block via Signal)
2. Macros verify Windows OS and .NET Framework v4.0.30319
3. COM hijack persistence: registers malicious prnfldr.dll at HKCU\Software\Classes\CLSID\{2227A280-3AEA-1069-A2DE-08002B30309D}\InProcServer32 — the Printers CLSID, loaded by explorer.exe at every logon
4. Steganography: windows.png (valid Windows background image) contains AES-CBC encrypted shellcode hidden in LSB of each pixel's RGBA values (4 bytes per pixel, LSB extraction)
5. Shellcode loads .NET Covenant/Grunt framework — GruntHTTPStager establishes API-driven channel to Koofr cloud storage
6. Downloads PlaySndSrv.dll + sample-03.wav → extracts BEARDSHELL C++ backdoor
7. BEARDSHELL uses IceDrive cloud storage for C2 — receives and executes PowerShell commands
8. SlimAgent spyware also observed on same compromised servers
Key Innovation: Signal Desktop MOTW bypass is the critical enabler. Microsoft's macro blocking policies (implemented 2022) are completely circumvented because Signal doesn't mark received files as internet-sourced.
=== CAMPAIGN 2: LAMEHUG — First LLM-Powered Malware (CERT-UA, Jul 2025) ===
Discovery: July 10, 2025, by CERT-UA. Published July 17, 2025. Attribution: APT28 with moderate confidence.
Target: Ukrainian government officials.
Attack Vector: Phishing emails impersonating Ukrainian ministry officials, containing ZIP archives with PyInstaller-compiled Python executables (.pif extension).
LLM Integration: LAMEHUG uses Qwen2.5-Coder-32B-Instruct model via Hugging Face API (approximately 270 tokens for authentication) to generate commands in real-time:
Prompt 1 (System Reconnaissance): 'Make a list of commands to create folder C:\Programdata\info and to gather computer information, hardware information, process and services information, networks information, AD domain information, to execute in one line and add each result to text file c:\Programdata\info\info.txt. Return only commands, without markdown.'
Prompt 2 (Document Harvesting): 'Make a list of commands to copy recursively different office and pdf/txt documents in user Documents, Downloads and Desktop folders to a folder c:\Programdata\info\ to execute in one line. Return only command, without markdown.'
The LLM generates comprehensive reconnaissance commands including: sy
Weaknesses (CWE)
CWE-79, CWE-94, CWE-434, CWE-287, CWE-200, CWE-532
Target sectors: Government, Military, Defense Industry, Logistics/Transportation, IT Services, Maritime, Air Traffic Management, Energy, Diplomatic, Education
Target regions: Ukraine, EU (Bulgaria, Romania, France, Germany, Greece, Italy, Netherlands, Poland, Czech Republic, Slovakia, Cyprus, Serbia), United States, Moldova, Ecuador, Cameroon, Central Asia (Kazakhstan, Tajikistan)
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 46 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, CVE-2024-11182, CVE-2023-43770, CVE-2024-27443, CVE-2023-23397, CVE-2023-38831, CVE-2020-35730, CVE-2020-12641, CVE-2021-44026, T1566, T1566, T1190, T1133, T1199, T1059, T1059, T1059, T1059, T1059