- Status
- Active
- Distinct actor
- LOW 58%
- Named actor
- INSUFFICIENT
- First observed
- 6 May 2026
- Last updated
- 11 Aug 2026
- Operator language
- Russian-speaking (HIGH)
- Motivation
- Financial crimeware
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-007 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.
Summary
Seven delivery vectors staged from sanctioned bulletproof hosting and beaconing to a second blocklisted provider. The operator's own contribution sits at the bundle layer, and a misspelled cloud-storage path stable across every vector for over a year is the load-bearing fingerprint. Two named clusters were ruled out on payload lineage.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
Broad opportunistic commodity targeting; no single industry narrowly targeted.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
busket/
operator cloud-storage path typo, stable across every delivery vector
Plowshare
operator project codename in a rebuilt component PDB
Infrastructure and tooling
- Primary host
62.60.237.100(the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)- Tooling
MITRE ATT&CK
40 techniques across 9 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.
T1027Obfuscated Files or InformationT1027.002Software PackingT1027.009Embedded PayloadsT1027.013Encrypted/Encoded FileT1036.002Right-to-Left OverrideT1036.005Match Legitimate Resource Name or LocationT1036.007Double File ExtensionT1055Process InjectionT1055.002Portable Executable InjectionT1055.012Process HollowingT1112Modify RegistryT1140Deobfuscate/Decode Files or InformationT1480Execution GuardrailsT1497.001System ChecksT1497.003Time Based ChecksT1553.004Install Root CertificateT1574.001DLLT1620Reflective Code Loading
Related designations
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.