Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-009
Multi-product fraud operator pairing a real VPN service with a brand-impersonation phishing library
Status
Active
Distinct actor
MODERATE 78%
Named actor
INSUFFICIENT
First observed
15 May 2026
Last updated
21 Aug 2026
Operator language
Russian-speaking (HIGH)
Motivation
Financial (HIGH)
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-009 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

A nearly three-year operation spanning a commercial VPN, a phishing subdomain library of several hundred brand impersonations, business-email burn domains and a fake exchange, across two sanctioned hosting providers. One supporting characteristic was withdrawn in August 2026 as a hosting-platform default and the report records that retraction.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Regions
RussiaIranChinaUnited States
Sectors
BankingEnterprise SaaSTelecom

Censorship-region VPN users, plus a brand-impersonation library against US banking, enterprise SaaS, Chinese internet firms and Russian telecom.

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

channel @inkconnectvpn operator Telegram channel, self-declares the parent brand
brand Inkognito operator parent brand
domain inklens.ru brand-impersonation phishing platform domain
domain inkconnect.ru VPN customer-facing domain
domain cryptone.bot fake-exchange front
string X-Admin-Token operator-designed custom API header
account-id 98466329 operator-controlled Yandex Webmaster ID

Infrastructure and tooling

Primary host
185.221.196.118 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
EspoCRM back-officeMarzban panelcustom web stack

MITRE ATT&CK

55 techniques across 12 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.

Persistence
Privilege Escalation

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.