SYMBOLCOMMON_NAMEaka. SYNONYMS

UAC-0020  (Back to overview)

aka: SickSync, TEMP.Vermin, VERMIN RELIC, Vermin

Vermin is a threat actor group linked to the Luhansk People’s Republic and believed to be acting on behalf of the Kremlin. They have targeted Ukrainian government infrastructure using malware like Spectr and legitimate tools like SyncThing for data exfiltration. Vermin has been active since at least 2018, using custom-made RATs like Vermin and open-source tools like Quasar for cyber-espionage. The group has resurfaced after periods of inactivity to conduct espionage operations against Ukraine's military and defense sectors.


Associated Families

There are currently no families associated with this actor.


References
2026-07-24GoogleGoogle Threat Intelligence Group
Updated Cyber Threat Actor Naming System
APT15 APT20 APT27 APT28 APT29 APT30 APT31 APT33 APT35 APT37 APT39 APT40 APT41 APT42 APT45 APT5 BlackTech Callisto Conference Crew FIN11 FIN6 FIN7 FIN8 MuddyWater MUSTANG PANDA Naikon OilRig Sandworm TEMP.Hermit Tick Tonto Team Turla UAC-0020 UNC1069 UNC1088 UNC2814
2024-06-07The RecordDaryna Antoniuk
Russia-linked Vermin hackers target Ukrainian military in new espionage campaign
UAC-0020
2024-06-05Cert-UACert-UA
UAC-0020 (Vermin) attacks the Defense Forces of Ukraine using the SPECTR SPZ in tandem with the legitimate SyncThing ("SickSync" campaign) (CERT-UA#9934)
UAC-0020
2022-03-21SOC PrimeAndrii Bezverkhyi
Vermin (UAC-0020) Hacking Collective Hits Ukrainian Government and Military with SPECTR Malware
Vermin UAC-0020

Credits: MISP Project