- Status
- Active
- Distinct actor
- MODERATE 68%
- Named actor
- INSUFFICIENT
- First observed
- 28 Feb 2026
- Last updated
- 1 Mar 2026
- Motivation
- Cybercrime, assessed as access brokering or post-access monetisation (HIGH)
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-001 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.
Summary
An operator whose complete Sliver build workspace was exposed on bulletproof hosting hours after an automated pipeline finished. The build fingerprint, a fraudulent code-signing certificate impersonating VMware, and a dual-beacon delivery design are the characteristics the designation rests on. No infrastructure overlap with any named campaign was found.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
No victim or targeting evidence was recovered; the toolkit was captured before deployment.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
659EEB5AA4A489FB238993AF259D23F057F6D6D6
fraudulent code-signing certificate serial, identifies the build pipeline
mailuxe.net
registered C2 domain
mailmassange.duckdns.org
backup C2 domain
Infrastructure and tooling
- Primary host
45.94.31.220(the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)- Tooling
MITRE ATT&CK
26 techniques across 7 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.
T1027.002Software PackingT1027.008Stripped PayloadsT1027.013Encrypted/Encoded FileT1036MasqueradingT1036.005Match Legitimate Resource Name or LocationT1055.008Ptrace System CallsT1055.012Process HollowingT1055.015ListPlantingT1070Indicator RemovalT1134.004Parent PID SpoofingT1140Deobfuscate/Decode Files or InformationT1497.001System ChecksT1497.003Time Based ChecksT1553.002Code SigningT1620Reflective Code Loading
Related designations
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.