#uac0010 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #uac0010, aggregated by home.social.
-
May 2026 Wave-2 Pterodo wrap:
- 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
- 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
- 0 takedown responses from @no-ip on my abuse@ submissions
- 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
- Microsoft Defender remains the single mainstream AV reliably catching the HTML stageActive campaign. Quiet public reporting. The asymmetry is the story.
Full notes: github.com/palianytsia-200/U-OB-KY
-
May 2026 Wave-2 Pterodo wrap:
- 14+ Pterodo HTML droppers on 212.193.20.110 over 2.5 months of observation
- 1 DDNS reactivation (babynet.serveirc.com, 2026-04-30)
- 0 takedown responses from @no-ip on my abuse@ submissions
- 0 new CERT-UA advisories (gap holds at 2023-07-13 → present, ~3 years)
- Microsoft Defender remains the single mainstream AV reliably catching the HTML stageActive campaign. Quiet public reporting. The asymmetry is the story.
Full notes: github.com/palianytsia-200/U-OB-KY
-
Detection-engineering shortlist for Wave-2 Pterodo (cheapest-defender-budget first):
1. Free / signature-based: Microsoft Defender `Trojan:HTML/Pterodo.HNAB!MTB` + ESET `VBS/Pterodo.CTH trojan` + Florian Roth's `SUSP_RAR_NTFS_ADS` YARA. Covers HTML stage + dropped RAR + implant stage.
2. Free / behavioural: Suricata rules on bare-IP HTTP egress + the documented verb corpus. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/
3. Free / network: any tool that flags HTTP `Host:` headers matching IPv4 literal from user endpoints. Bare-IP egress is unusual at scale.
Mainstream AV catches ~5% of Wave-2 samples on initial detonation. Defense moves upstream of AV signatures.
-
Detection-engineering shortlist for Wave-2 Pterodo (cheapest-defender-budget first):
1. Free / signature-based: Microsoft Defender `Trojan:HTML/Pterodo.HNAB!MTB` + ESET `VBS/Pterodo.CTH trojan` + Florian Roth's `SUSP_RAR_NTFS_ADS` YARA. Covers HTML stage + dropped RAR + implant stage.
2. Free / behavioural: Suricata rules on bare-IP HTTP egress + the documented verb corpus. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/
3. Free / network: any tool that flags HTTP `Host:` headers matching IPv4 literal from user endpoints. Bare-IP egress is unusual at scale.
Mainstream AV catches ~5% of Wave-2 samples on initial detonation. Defense moves upstream of AV signatures.
-
Operator-side locale dissonance I keep noticing on Wave-2 Pterodo:
- Filename schema: `DD.MM.YYYY` (Russian / European locale)
- Beacon URL verbs: `Akad`, `Mouuds`, `Svvr` — English / Latin root selection
- HTML lander Content-Language meta: usually `ru-RU`
- Document body text: Ukrainian / Russian mixThe automation pipeline is configured for Russian locale, but the URL-generator lexicon picks English-rooted strings. Old code by Russian-speaking authors who wrote the URL-gen with an English mental-model 5+ years ago?
Has anyone seen this fingerprint on other Russian APT pipelines (Sandworm, APT28)? Curious if UAC-0010-specific or broader.
-
Operator-side locale dissonance I keep noticing on Wave-2 Pterodo:
- Filename schema: `DD.MM.YYYY` (Russian / European locale)
- Beacon URL verbs: `Akad`, `Mouuds`, `Svvr` — English / Latin root selection
- HTML lander Content-Language meta: usually `ru-RU`
- Document body text: Ukrainian / Russian mixThe automation pipeline is configured for Russian locale, but the URL-generator lexicon picks English-rooted strings. Old code by Russian-speaking authors who wrote the URL-gen with an English mental-model 5+ years ago?
Has anyone seen this fingerprint on other Russian APT pipelines (Sandworm, APT28)? Curious if UAC-0010-specific or broader.
-
PSA for anyone with Ukrainian-org exposure: Pterodo Wave-2 droppers chain CVE-2025-8088 + CVE-2025-6218 (WinRAR ADS path-traversal + co-exploit). Both patched in WinRAR 7.13.
A lot of UA orgs run WinRAR like a "forever tool" — installed 5 years ago, never updated. That's the soft target for this campaign.
Audit your endpoint inventory. WinRAR ≤7.12 is not a "next sprint" item.
Signatures: ESET `VBS/Pterodo.CTH trojan` on the dropped VBS implant. Florian Roth's `SUSP_RAR_NTFS_ADS` YARA on the archive itself.
-
PSA for anyone with Ukrainian-org exposure: Pterodo Wave-2 droppers chain CVE-2025-8088 + CVE-2025-6218 (WinRAR ADS path-traversal + co-exploit). Both patched in WinRAR 7.13.
A lot of UA orgs run WinRAR like a "forever tool" — installed 5 years ago, never updated. That's the soft target for this campaign.
Audit your endpoint inventory. WinRAR ≤7.12 is not a "next sprint" item.
Signatures: ESET `VBS/Pterodo.CTH trojan` on the dropped VBS implant. Florian Roth's `SUSP_RAR_NTFS_ADS` YARA on the archive itself.
-
Hi @no-ip — confirmed today: babynet.serveirc.com → 212.193.20.110.
That's the 19th No-IP family DDNS hostname on the live Pterodo Wave-2 C2 IP. Every subdomain rotation since 2025-12-26 has gone through No-IP. PDF-themed lure names (google-pdf.redirectme.net, onlinepdf.serveftp.com, acess-pdf.webhop.me — including the persistent "acess" typo).
Full table + takedown bundle (single abuse@ submission, all 19 hostnames, Pterodo attribution, ESET signature ref): github.com/palianytsia-200/U-OB-KY/blob/main/iocs/ddns_frontends.md
[email protected] — your team's 10-minute job.
-
Hi @no-ip — confirmed today: babynet.serveirc.com → 212.193.20.110.
That's the 19th No-IP family DDNS hostname on the live Pterodo Wave-2 C2 IP. Every subdomain rotation since 2025-12-26 has gone through No-IP. PDF-themed lure names (google-pdf.redirectme.net, onlinepdf.serveftp.com, acess-pdf.webhop.me — including the persistent "acess" typo).
Full table + takedown bundle (single abuse@ submission, all 19 hostnames, Pterodo attribution, ESET signature ref): github.com/palianytsia-200/U-OB-KY/blob/main/iocs/ddns_frontends.md
[email protected] — your team's 10-minute job.
-
Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.
UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.
I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.
github.com/palianytsia-200/U-OB-KY
-
Friendly reminder: CERT-UA's last public UAC-0010 (Gamaredon) advisory was 2023-07-13. That's almost three years of public silence on the most prolific Russian APT targeting Ukraine.
UAC-0010 samples on VT have not slowed down. Public reporting has. The defender community has lost its single best public feed for in-the-clear Gamaredon IOCs.
I started U-OB-KY in late 2024 partly to fill that gap for myself. If anyone else has the bandwidth to do similar — please do. The more distributed the public picture, the harder it is to silence.
github.com/palianytsia-200/U-OB-KY
-
Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.
14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.
Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules
-
Whichever automation team at UAC-0010 designed the `Scan_<X>_<Y>_<Z>_<NNNN>_<DD.MM.YYYY>.htm` filename schema — congrats, you automated your own signature.
14 samples across 2 months, zero variation. The `Scan_` prefix was added 2026-04-29 — social-engineering touch ("scanned document, today's date" clicks better). The `_DD.MM.YYYY.htm` suffix anchors a near-perfect mail-gateway regex until they decide to drop it.
Detection at the mail gateway is the cheapest defense. Drafts in github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-filename.rules
-
Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):
/(Svvr|SSsr|Akad|Akk|Gpps|Mouuds)(Htm|Ua|U)?-DD-MM → 212.193.20.110
5 of 6 verbs carry double-letter alliteration (vv/Ss/kk/pp/uu) — same operator habit as the 2022-23 `j-j-j` URL generator + the alliterative *orious.ru / *mucoris.ru apex naming Talos/Symantec documented years ago. Three years later, same fingerprint.
Bare-IP + plain HTTP + no TLS = SNI inspection won't catch it. Block 212.193.20.110 directly.
Suricata draft rules: github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-wave2-beacon.rules
-
Wave-2 Pterodo beacon URL pattern (n=14 samples since 2026-02):
/(Svvr|SSsr|Akad|Akk|Gpps|Mouuds)(Htm|Ua|U)?-DD-MM → 212.193.20.110
5 of 6 verbs carry double-letter alliteration (vv/Ss/kk/pp/uu) — same operator habit as the 2022-23 `j-j-j` URL generator + the alliterative *orious.ru / *mucoris.ru apex naming Talos/Symantec documented years ago. Three years later, same fingerprint.
Bare-IP + plain HTTP + no TLS = SNI inspection won't catch it. Block 212.193.20.110 directly.
Suricata draft rules: github.com/palianytsia-200/U-OB-KY/blob/main/rules/pterodo-wave2-beacon.rules
-
Finally pushed my Pterodo / UAC-0010 tracker public after sitting in a private gitea for a year+: github.com/palianytsia-200/U-OB-KY
Personal notes since late 2024 (when CERT-UA went quiet on UAC-0010 — last public advisory 2023-07-13). IOC tracksheets, dated research notes, draft Suricata rules.
Current focus: Wave-2 HTML lander batch on 212.193.20.110, RAR droppers chaining CVE-2025-8088 + CVE-2025-6218 via NTFS ADS. Notes in `notes/2026-05-rar-exploit-chain.md`.
VT free tier so this is not a feed — just one person's running notes. Comments / corrections welcome.
-
Finally pushed my Pterodo / UAC-0010 tracker public after sitting in a private gitea for a year+: github.com/palianytsia-200/U-OB-KY
Personal notes since late 2024 (when CERT-UA went quiet on UAC-0010 — last public advisory 2023-07-13). IOC tracksheets, dated research notes, draft Suricata rules.
Current focus: Wave-2 HTML lander batch on 212.193.20.110, RAR droppers chaining CVE-2025-8088 + CVE-2025-6218 via NTFS ADS. Notes in `notes/2026-05-rar-exploit-chain.md`.
VT free tier so this is not a feed — just one person's running notes. Comments / corrections welcome.