- Status
- Active
- Distinct actor
- MODERATE 72%
- Named actor
- INSUFFICIENT
- First observed
- 15 May 2026
- Last updated
- 15 May 2026
- Motivation
- Financial
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-010 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.
Summary
The customer-side operator of a commodity infostealer, identified by a homebrew loader with zero-public-hit strings, an unusual key length and a hollowing target no other documented customer uses, calling back to a C2 that stayed stable for almost three years and outlived a law-enforcement takedown. The stealer's vendor is a separate, well-documented target and is explicitly outside this designation.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
Opportunistic; delivered via cracked-software and game-cheat lures.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
79.133.180.168
operator C2 endpoint, stable for about 34 months
BombAUb23456
zero-public-hit operator string in the loader
DubzAias932
zero-public-hit operator string in the loader
take it everywhere
operator personality marker logged by the loader
Infrastructure and tooling
- Primary host
79.137.192.3(the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)- Tooling
MITRE ATT&CK
39 techniques across 11 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.
T1027Obfuscated Files or InformationT1027.002Software PackingT1027.007Dynamic API ResolutionT1027.011Fileless StorageT1027.013Encrypted/Encoded FileT1070.004File DeletionT1140Deobfuscate/Decode Files or InformationT1480.002Mutual ExclusionT1497Virtualization/Sandbox EvasionT1497.003Time Based ChecksT1622Debugger Evasion
Related designations
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.