PULSE NAME
UAC-0252 cyberattacks with SHADOWSNIFF and SALATSTEALER stealers
WHITE PetrP.73 2026-03-18 Modified: 2026-04-17
52
IOCs
HIGH VOLUME
Since January 2026, CERT-UA has been monitoring a series of cyberattacks attributed to the group identified as UAC-0252. These attacks utilize social engineering tactics, with attackers masquerading as representatives from central executive authorities and regional administrations, urging targets to update mobile applications that are widely used in both civilian and military sectors. The malicious communications often include attachments disguised as archives containing executable files or links to legitimate websites that carry vulnerabilities, specifically those susceptible to Cross-Site Scripting (XSS). Upon interacting with these links, users may inadvertently download harmful executables under the influence of JavaScript code.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
Indicators of Compromise (12 / 52 total)
All CVE FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 2591d145ff510f7fc4d6290d3bfcb130 2026-03-18
FileHash-MD5 510690f2a21e677f05094e4fcfea9a9a 2026-03-18
FileHash-MD5 6ba7f82518e76a436d5eeb50f626d218 2026-03-18
FileHash-MD5 974cc318d509301be0966cc1b397076b 2026-03-18
FileHash-MD5 9a9a98117b483439cf54c9f7ffa4e417 2026-03-18
FileHash-MD5 a3e8f8dc8702474452b1b0889a9d77d1 2026-03-18
FileHash-MD5 b6480aa6c364715a21ba28c4d26a5b6e MD5 of c2a4212573d7566acf5b610b4ce3598237acd37459670daa1b6950f107d50e03 2026-03-18
FileHash-MD5 c2b70e79a3c7e9d392b02da9d7265d1f 2026-03-18
FileHash-MD5 cdc1919fc612772b34daecbcf2e38a05 2026-03-18
FileHash-MD5 dcc2c9a08044e8b3e445f17461d054f1 MD5 of 7b35b332a999d56d65241a4f35bbce2e9ad2644a84c09f7dbae42e39cd559bcf 2026-03-18
FileHash-MD5 e457cb42ca5a6ecd8b99d89ed2958b29 MD5 of b5e685e57c625032ec067be94a2854cce1b7c5a51e8d6bd833841a893d5d88b7 2026-03-18
FileHash-MD5 f3dc1e16cde2995f701c8db509f351c9 MD5 of e5941df780ae251bcafad3b833f45ee44bd1599ab45b7adf1f1c79510930642d 2026-03-18