The cyber landscape in Eastern Europe remains fraught with peril as the Russia-aligned threat actor UAC-0184 has been observed actively exploiting the Viber messaging platform to target Ukrainian military and government entities. This campaign, ongoing since 2025, highlights the evolving tactics, techniques, and procedures (TTPs) employed by nation-state actors in intelligence gathering. The attacks involve the distribution of malicious ZIP archives through Viber, a widely used messaging app in the region.
UAC-0184's Persistent Campaign
According to the 360 Threat Intelligence Center, UAC-0184 has demonstrated a sustained focus on Ukrainian targets throughout 2025, and this activity continues into the new year. The group's persistence underscores the strategic importance of intelligence gleaned from these sectors, particularly amidst the ongoing geopolitical tensions. This is not a novel tactic. Messaging platforms, due to their ubiquity and perceived security, often serve as an effective attack vector for initial access.
Technical Details and Impact
While specific CVE identifiers related to the Viber vulnerability being exploited are currently unconfirmed, the use of malicious ZIP archives suggests a potential reliance on social engineering to entice users into executing embedded payloads. The specific malware deployed in these attacks remains under investigation, but initial reports point towards information stealers designed to exfiltrate sensitive data from compromised systems. Given Viber's extensive user base within Ukrainian government and military circles, the potential for widespread compromise is significant. The attack surface is broad and requires immediate attention.
Broader Implications and Mitigation
The UAC-0184 campaign serves as a stark reminder of the critical need for robust cybersecurity measures within government and military organizations. Employees must be vigilant against suspicious attachments and links received through messaging applications. Furthermore, organizations should implement multi-factor authentication, endpoint detection and response (EDR) solutions, and comprehensive security awareness training programs to mitigate the risk of successful exploitation. This incident also underscores the growing trend of nation-state actors leveraging popular communication platforms for espionage, a trend that demands constant vigilance and adaptation. While no specific CVSS score can be attached to the vulnerability at this time, the high-profile nature of the targets and the potential for significant data exfiltration warrant immediate action.