FlagThis
← Threat Actors
/
unknown
/
UAC-0185
DOSSIER // UAC-0185
UAC-0185
ACTIVE CAMPAIGN TRACKED
▲ High Threat
unknown
Primary Aliases:
APT28
FANCY BEAR
Forest Blizzard
LAUNDRY BEAR
🔍 Adversary Rosetta Stone (49) ▾
📋 Copy All
Sponsor / State Affiliation
unknown
Primary Motivation
Espionage
Active Timeline
Unknown – Present
Confidence Rating
85% (Grounded)
Edge Device Vulnerability Exploitation, Custom Malware Deployment Operations
📥 Export ATT&CK Layer (.json)
🔔 RSS Feed
🏛️ CISA Advisories ↗
📋 Copy Dossier Briefing
⚔️ Weaponized CVE Matrix
(0)
No specific weaponized CVEs currently mapped in the public baseline.
🎯 Target Sectors & Focus
Government
Defense
Aerospace
Telecommunications
Critical Infrastructure
🛡️ MITRE ATT&CK® Attack Lifecycle
(6 TTPs)
📥 Download Navigator JSON
All Stages
6
Initial Access
2
Execution
1
Credential Access & Discovery
1
Lateral Movement & Collection
1
Command & Control
1
Initial Access
2
T1190
Exploit Public-Facing Application
↗
T1078
Valid Accounts
↗
Execution
1
T1059
Command and Scripting Interpreter
↗
Credential Access & Discovery
1
T1003
OS Credential Dumping
↗
Lateral Movement & Collection
1
T1021
Remote Services / Lateral Movement
↗
Command & Control
1
T1071
Custom Malware Deployment (RottenShrew/Lost Potential)
↗
📰 Verified Campaigns & Intelligence Archive
🔔 Subscribe to Alerts
[DEEP DIVE]
U.S. State Department Issues $10M Bounty Targeting UNC5792 and UNC4221 via Signal and WhatsApp Phishing Campaigns
Strategies and Tactics
2026-07-04
[DEEP DIVE]
APT28 Deploys HOOKEDGE Backdoor via webhook.site in Diplomatic Espionage Campaign
Attacks and Vulnerabilities
2026-08-29
[DEEP DIVE]
Russian APT28 Campaign Leveraging HOOKEDGE and webhook.site for European Espionage
Attacks and Vulnerabilities
2026-08-28
[DEEP DIVE]
GREYVIBE Leverages ChatGPT and Google Gemini for AI-Augmented Operations against Ukraine
Attacks and Vulnerabilities
2026-07-05
[DEEP DIVE]
APT28 and LameHug: AI-Driven Dynamic Command Generation
Attacks and Vulnerabilities
2026-07-03
[DEEP DIVE]
APT28 Exploitation of Edge Device Vulnerabilities and EOL Hardware
Attacks and Vulnerabilities
2026-06-19
Adversary Rosetta Stone // UAC-0185
×
🪟 Microsoft Threat Actor Naming
Forest Blizzard
📋
STRONTIUM
📋
Void Blizzard
📋
🦅 CrowdStrike Monikers
FANCY BEAR
📋
LAUNDRY BEAR
📋
🔍 Mandiant / Google Threat Intel
APT28
📋
UNC4221
📋
🏛️ Government / CISA / Law Enforcement
Unit 26165
📋
🛡️ Other Industry Tracking Codes
85th Main Special Service Center
📋
APT-C-20
📋
ATG2
📋
ATK5
📋
Blue Athena
📋
BlueDelta
📋
CL-STA-1114
📋
CrisisFour
📋
Fighting Ursa
📋
FROZENLAKE
📋
G0007
📋
Grey-Cloud
📋
Grizzly Steppe
📋
Group 74
📋
Group M
📋
GruesomeLarch
📋
HELLFIRE
📋
IRON TWILIGHT
📋
ITG05
📋
KTA007
📋
LAKE RELIC
📋
Lost Potential
📋
Pawn Storm
📋
RottenShrew
📋
Sednit
📋
SIG40
📋
SNAKEMACKEREL
📋
Sofacy
📋
Swallowtail
📋
T-APT-12
📋
TA422
📋
TA488
📋
TAG-0700
📋
TG-4127
📋
Threat Group-4127
📋
Tsar Team
📋
UAC-0001
📋
UAC-0028
📋
UAC-0190
📋
UNK_PitStop
📋
Z-Lom Team
📋
Copied to clipboard
SHARE INTELLIGENCE WIRE
×
Story Title
X / Twitter
Bluesky
LinkedIn
Copy Link
LINK COPIED TO CLIPBOARD