- Status
- Active
- Distinct actor
- Tracked as a cluster; no figure published
- Named actor
- INSUFFICIENT
- First observed
- 3 Aug 2026
- Last updated
- 3 Aug 2026
- Motivation
- Access and persistence; single operator versus sold builder deliberately unresolved
Note on UTA identifiers: "UTA" stands for Unattributed Threat Actor. UTA-2026-021 is a tracking label The Hunters Ledger assigns to an actor I have observed but cannot yet link to a publicly named threat group. Other vendors and feeds will not use this label; it is specific to this publication. If later evidence ties the activity to a named actor, I will retire the label and update the report.
Summary
A 22-file toolkit built almost entirely from other people's tooling, with components publicly tied to three unrelated named actors, none of which is the operator. Named attribution is insufficient by refutation rather than by absence, and the designation is anchored on the infrastructure estate and a target-specific orchestrator.
The confidence levels above are the published report's figures. Every claim on this page is a summary of the linked reports, which remain the record.
Targeting
Anchored on the infrastructure and a target-specific orchestrator; the kit-author identifiers in the toolkit are not this operator's.
Targeting is given as region and sector, drawn from the reports. Victim names are deliberately not published here or in the reports.
Reports
Actor identifiers
Artifacts this operator chose or created: handles, channels, operator brands and domains, wallets and the like. Each is printed in a report linked above; the full indicator set, with its caveats, is in each report's IOC feed.
91.92.43.221
dedicated operator C2 host
2.27.248.138
dedicated operator C2 host
WinUpdateService
operator service-masquerade name
[C2_END]
operator C2 message terminator (later build)
Infrastructure and tooling
- Primary host
91.197.98.188(the operator-controlled host the assigning report is named for; the full indicator set, with its caveats, is in each report's IOC feed)- Tooling
MITRE ATT&CK
54 techniques across 13 tactics, read from the mapping tables of the reports about this actor. Each technique links to where it is mapped.
T1027Obfuscated Files or InformationT1036.005Match Legitimate Resource Name or LocationT1055Process InjectionT1070Indicator RemovalT1112Modify RegistryT1127.001MSBuildT1140Deobfuscate/Decode Files or InformationT1497Virtualization/Sandbox EvasionT1564.002Hidden UsersT1620Reflective Code Loading
Actor profiles and the reports behind them are © Joseph, The Hunter's Ledger, licensed CC BY 4.0: free to use, including commercially, with attribution. All tracked actors.