Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0094

Description

State Service of Special Communication and Information Protection of Ukraine spotted a new wave of cyber attacks aimed at gaining access to users’ Telegram accounts. The Ukrainian CERT attributes the hacking campaign to threat actors tracked as UAC-0094. Threat actors are targeting Telegram users by sending Telegram messages with malicious links to the Telegram website in order to gain unauthorized access to the records and transfer a one-time code from SMS.

AI Analysis

· 1 week ago

Executive Summary

The threat actor UAC-0094 is targeting Telegram users through phishing attacks, aiming to steal SMS-based one-time codes for potential financial gain or espionage.

Goals & Targeting

UAC-0094 likely targets individuals and possibly businesses using Telegram in Ukraine and potentially other regions. Their primary goals appear to include financial gain through identity theft or fraud, with possible secondary objectives such as espionage if targeting specific groups or sensitive information.

Enhanced Description

UAC-0094 has been identified by the Ukrainian CERT as a cyber actor conducting campaigns that exploit Telegram vulnerabilities. The group sends malicious links via Telegram messages, directing users to fake websites to compromise their accounts and intercept SMS codes. This tactic indicates a focus on individual or small-scale targets rather than large organizations, although the broader impact could extend beyond Ukraine.

Key Capabilities

  • Spear-phishing via Telegram messages
  • Malware deployment for SMS code interception
  • Social engineering techniques

MITRE ATT&CK Tactics

Credential Access
Collection

ATT&CK Techniques

T1566.001 - Exfiltration Over Network Server
T1547.003 - Social Media Phishing

Software / Tooling

Custom phishing scripts
SMS intercept malware

Campaigns & Victims

UAC-0094's campaigns exhibit consistent targeting of Telegram users, likely individuals and small businesses. Their operational tempo is steady but not widely documented beyond the initial reports.

IOC Patterns

  • Phishing links embedded in Telegram messages
  • Unusual login attempts from non-standard IPs

Recommended Actions

  • Educate users on phishing risks via messaging apps
  • Implement multi-factor authentication for sensitive accounts
  • Monitor for anomalies in SMS-based transactions

Suggested Tags

cyber espionage
phishing
Ukraine

Confidence Assessment

Low confidence due to limited details on UAC-0094's full capabilities and past campaigns outside of the described phishing activities. More data would enhance understanding.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

cyber espionage
phishing
Ukraine

Details

Type
Unknown
Country of Origin
R
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.