- Status
- Active
- Distinct actor
- MODERATE 75%
- Named actor
- INSUFFICIENT
- First observed
- 15 May 2026
- Last updated
- 16 May 2026
- Operator language
- Turkish-speaking
- Motivation
- Financial, Turkish consumer fraud
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-008 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.
Summary
A phishing panel and seven brand-impersonation kits recovered in full source from a multi-tenant staging host. A developer signature hard-coded into function names and a single shared database across the panel and every kit rule out a leaked template and point to one developer-operator. First public documentation of the panel.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
@AresRS34
operator Telegram alias
Wadanz
developer pseudonym hard-coded in function names
BellaMain
phishing-as-a-service panel brand
5606327063
admin Telegram UID (withdrawal approver)
-1002104835510
operator Telegram group
Infrastructure and tooling
- Primary host
79.137.192.3(the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)- Tooling
MITRE ATT&CK
57 techniques across 12 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.
T1027Obfuscated Files or InformationT1027.002Software PackingT1027.007Dynamic API ResolutionT1027.011Fileless StorageT1027.013Encrypted/Encoded FileT1036.005Match Legitimate Resource Name or LocationT1070Indicator RemovalT1070.004File DeletionT1140Deobfuscate/Decode Files or InformationT1480Execution GuardrailsT1480.002Mutual ExclusionT1497Virtualization/Sandbox EvasionT1497.003Time Based ChecksT1622Debugger Evasion
Related designations
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.