FlyingYeti is a Russia-aligned threat actor that emerged with documented activity as UAC-0149 in at least the fall of 2023, primarily targeting Ukrainian defense entities. The group focuses on cyber espionage and data exfiltration. They are known for exploiting current events, such as the lifting of Ukraine's moratorium on utility debt, to craft highly effective phishing lures. FlyingYeti operates under the alias UAC-0149, a designation used by the Computer Emergency Response Team of Ukraine, and has also been referred to as Flying Yeti and Storm-1837.