home.social

#uac0010 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #uac0010, aggregated by home.social.

fetched live
  1. May 2026 Wave-2 Pterodo wrap:

    - 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
    - 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
    - 0 takedown responses from @no-ip on my abuse@ submissions
    - 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
    - Microsoft Defender remains the single mainstream AV reliably catching the HTML stage

    Active campaign. Quiet public reporting. The asymmetry is the story.

    Full notes: github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  2. May 2026 Wave-2 Pterodo wrap:

    - 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
    - 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
    - 0 takedown responses from @no-ip on my abuse@ submissions
    - 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
    - Microsoft Defender remains the single mainstream AV reliably catching the HTML stage

    Active campaign. Quiet public reporting. The asymmetry is the story.

    Full notes: github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  3. Detection-engineering shortlist for Wave-2 Pterodo (cheapest-defender-budget first):

    1. Free / signature-based: Microsoft Defender `Trojan:HTML/Pterodo.HNAB!MTB` + ESET `VBS/Pterodo.CTH trojan` + Florian Roth's `SUSP_RAR_NTFS_ADS` YARA. Covers HTML stage + dropped RAR + implant stage.

    2. Free / behavioural: Suricata rules on bare-IP HTTP egress + the documented verb corpus. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/

    3. Free / network: any tool that flags HTTP `Host:` headers matching IPv4 literal from user endpoints. Bare-IP egress is unusual at scale.

    Mainstream AV catches ~5% of Wave-2 samples on initial detonation. Defense moves upstream of AV signatures.

    #Pterodo #UAC0010 #DetectionEngineering #ThreatIntel

  4. Detection-engineering shortlist for Wave-2 Pterodo (cheapest-defender-budget first):

    1. Free / signature-based: Microsoft Defender `Trojan:HTML/Pterodo.HNAB!MTB` + ESET `VBS/Pterodo.CTH trojan` + Florian Roth's `SUSP_RAR_NTFS_ADS` YARA. Covers HTML stage + dropped RAR + implant stage.

    2. Free / behavioural: Suricata rules on bare-IP HTTP egress + the documented verb corpus. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/

    3. Free / network: any tool that flags HTTP `Host:` headers matching IPv4 literal from user endpoints. Bare-IP egress is unusual at scale.

    Mainstream AV catches ~5% of Wave-2 samples on initial detonation. Defense moves upstream of AV signatures.

    #Pterodo #UAC0010 #DetectionEngineering #ThreatIntel

  5. Operator-side locale dissonance I keep noticing on Wave-2 Pterodo:

    - Filename schema: `DD.MM.YYYY` (Russian / European locale)
    - Beacon URL verbs: `Akad`, `Mouuds`, `Svvr` — English / Latin root selection
    - HTML lander Content-Language meta: usually `ru-RU`
    - Document body text: Ukrainian / Russian mix

    The automation pipeline is configured for Russian locale, but the URL-generator lexicon picks English-rooted strings. Old code by Russian-speaking authors who wrote the URL-gen with an English mental-model 5+ years ago?

    Has anyone seen this fingerprint on other Russian APT pipelines (Sandworm, APT28)? Curious if UAC-0010-specific or broader.

    #Pterodo #UAC0010 #ThreatIntel

  6. Operator-side locale dissonance I keep noticing on Wave-2 Pterodo:

    - Filename schema: `DD.MM.YYYY` (Russian / European locale)
    - Beacon URL verbs: `Akad`, `Mouuds`, `Svvr` — English / Latin root selection
    - HTML lander Content-Language meta: usually `ru-RU`
    - Document body text: Ukrainian / Russian mix

    The automation pipeline is configured for Russian locale, but the URL-generator lexicon picks English-rooted strings. Old code by Russian-speaking authors who wrote the URL-gen with an English mental-model 5+ years ago?

    Has anyone seen this fingerprint on other Russian APT pipelines (Sandworm, APT28)? Curious if UAC-0010-specific or broader.

    #Pterodo #UAC0010 #ThreatIntel

  7. PSA for anyone with Ukrainian-org exposure: Pterodo Wave-2 droppers chain CVE-2025-8088 + CVE-2025-6218 (WinRAR ADS path-traversal + co-exploit). Both patched in WinRAR 7.13.

    A lot of UA orgs run WinRAR like a "forever tool" — installed 5 years ago, never updated. That's the soft target for this campaign.

    Audit your endpoint inventory. WinRAR ≤7.12 is not a "next sprint" item.

    Signatures: ESET `VBS/Pterodo.CTH trojan` on the dropped VBS implant. Florian Roth's `SUSP_RAR_NTFS_ADS` YARA on the archive itself.

    #WinRAR #CVE_2025_8088 #Pterodo #UAC0010 #ThreatIntel

  8. PSA for anyone with Ukrainian-org exposure: Pterodo Wave-2 droppers chain CVE-2025-8088 + CVE-2025-6218 (WinRAR ADS path-traversal + co-exploit). Both patched in WinRAR 7.13.

    A lot of UA orgs run WinRAR like a "forever tool" — installed 5 years ago, never updated. That's the soft target for this campaign.

    Audit your endpoint inventory. WinRAR ≤7.12 is not a "next sprint" item.

    Signatures: ESET `VBS/Pterodo.CTH trojan` on the dropped VBS implant. Florian Roth's `SUSP_RAR_NTFS_ADS` YARA on the archive itself.

    #WinRAR #CVE_2025_8088 #Pterodo #UAC0010 #ThreatIntel

  9. Hi @no-ip — confirmed today: babynet.serveirc.com → 212.193.20.110.

    That's the 19th No-IP family DDNS hostname on the live Pterodo Wave-2 C2 IP. Every subdomain rotation since 2025-12-26 has gone through No-IP. PDF-themed lure names (google-pdf.redirectme.net, onlinepdf.serveftp.com, acess-pdf.webhop.me — including the persistent "acess" typo).

    Full table + takedown bundle (single abuse@ submission, all 19 hostnames, Pterodo attribution, ESET signature ref): github.com/palianytsia-200/U-OB-KY/blob/main/iocs/ddns_frontends.md

    [email protected] — your team's 10-minute job.

    #Pterodo #UAC0010 #abuseDNS #ThreatIntel

  10. Hi @no-ip — confirmed today: babynet.serveirc.com → 212.193.20.110.

    That's the 19th No-IP family DDNS hostname on the live Pterodo Wave-2 C2 IP. Every subdomain rotation since 2025-12-26 has gone through No-IP. PDF-themed lure names (google-pdf.redirectme.net, onlinepdf.serveftp.com, acess-pdf.webhop.me — including the persistent "acess" typo).

    Full table + takedown bundle (single abuse@ submission, all 19 hostnames, Pterodo attribution, ESET signature ref): github.com/palianytsia-200/U-OB-KY/blob/main/iocs/ddns_frontends.md

    [email protected] — your team's 10-minute job.

    #Pterodo #UAC0010 #abuseDNS #ThreatIntel

  11. Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.

    UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.

    I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.

    github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  12. Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.

    UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.

    I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.

    github.com/palianytsia-200/U-OB-KY

    #Pterodo #UAC0010 #UkraineCyber #ThreatIntel

  13. Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.

    14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.

    Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules

    #Pterodo #UAC0010 #UkraineCyber

  14. Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.

    14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.

    Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules

    #Pterodo #UAC0010 #UkraineCyber

  15. Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):

    /(Svvr|SSsr|Akad|Akk|Gpps|Mouuds)(Htm|Ua|U)?-DD-MM → 212.193.20.110

    5 of 6 verbs carry double-letter alliteration (vv/Ss/kk/pp/uu) — same operator habit as the 2022-23 `j-j-j` URL generator + the alliterative *orious.ru / *mucoris.ru apex naming Talos/Symantec documented years ago. Three years later, same fingerprint.

    Bare-IP + plain HTTP + no TLS = SNI inspection won't catch it. Block 212.193.20.110 directly.

    Suricata draft rules: github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-wave2-beacon.rules

    #Pterodo #UAC0010 #Gamaredon #ThreatIntel

  16. Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):

    /(Svvr|SSsr|Akad|Akk|Gpps|Mouuds)(Htm|Ua|U)?-DD-MM → 212.193.20.110

    5 of 6 verbs carry double-letter alliteration (vv/Ss/kk/pp/uu) — same operator habit as the 2022-23 `j-j-j` URL generator + the alliterative *orious.ru / *mucoris.ru apex naming Talos/Symantec documented years ago. Three years later, same fingerprint.

    Bare-IP + plain HTTP + no TLS = SNI inspection won't catch it. Block 212.193.20.110 directly.

    Suricata draft rules: github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-wave2-beacon.rules

    #Pterodo #UAC0010 #Gamaredon #ThreatIntel

  17. Finally pushed my Pterodo / UAC-0010 tracker public after sitting in a private gitea for a year+: github.com/palianytsia-200/U-OB-KY

    Personal notes since late 2024 (when CERT-UA went quiet on UAC-0010 — last public advisory 2023-07-13). IOC tracksheets, dated research notes, draft Suricata rules.

    Current focus: Wave-2 HTML lander batch on 212.193.20.110, RAR droppers chaining CVE-2025-8088 + CVE-2025-6218 via NTFS ADS. Notes in `notes/2026-05-rar-exploit-chain.md`.

    VT free tier so this is not a feed — just one person's running notes. Comments / corrections welcome.

    #Pterodo #UAC0010 #Gamaredon #ThreatIntel

  18. Finally pushed my Pterodo / UAC-0010 tracker public after sitting in a private gitea for a year+: github.com/palianytsia-200/U-OB-KY

    Personal notes since late 2024 (when CERT-UA went quiet on UAC-0010 — last public advisory 2023-07-13). IOC tracksheets, dated research notes, draft Suricata rules.

    Current focus: Wave-2 HTML lander batch on 212.193.20.110, RAR droppers chaining CVE-2025-8088 + CVE-2025-6218 via NTFS ADS. Notes in `notes/2026-05-rar-exploit-chain.md`.

    VT free tier so this is not a feed — just one person's running notes. Comments / corrections welcome.

    #Pterodo #UAC0010 #Gamaredon #ThreatIntel