Skip to content
THE HUNTER’S LEDGER
Threat Actor
UTA-2026-012 bandcampro (Trend Micro)
AI-augmented credential-mill operator using an LLM for per-target password mutation
Status
Active
Distinct actor
MODERATE 83%
Named actor
INSUFFICIENT
First observed
25 May 2026
Last updated
31 Aug 2026
Operator language
Russian-native (DEFINITE)
Motivation
Financial, with a co-located political disinformation sideline
Also tracked as
bandcampro (Trend Micro)
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-012 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.

Summary

A mid-tier operator who orchestrated a credential mill through an AI command-line agent, ran an operator-built unauthenticated C2, and tunnelled persistent access into a US healthcare victim through named tunnels under an operator-owned domain. Trend Micro independently documented the same operator under its own tracking handle, which the report pairs with the designation rather than retiring it.

The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.

Targeting

Regions
United States
Sectors
Healthcare

Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.

Reports

Actor identifiers

Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.

handle sonner1337 operator GitHub handle
channel @americanpatriotus operator Telegram channel (co-located disinformation)
domain tralalarkefe.com operator-owned domain fronting named C2 tunnels

Infrastructure and tooling

Primary host
213.165.51.115 (the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)
Tooling
Gemini CLIcustom Python C2Cloudflare Tunnelnuclei

MITRE ATT&CK

21 techniques across 10 tactics, read from the mapping tables of the reports about this actor, which keep their mapping on the companion detection page. Each technique links to where it is mapped.

Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.