Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Threat Actors UAC-0050

Description

UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine. They have been distributing the Remcos RAT malware through phishing campaigns, using tactics such as impersonating the Security Service of Ukraine and sending emails with malicious attachments. The group has also been linked to other hacking collectives, such as UAC-0096, and has previously used remote administration tools like Remote Utilities. The motive behind their attacks is likely espionage.

AI Analysis

· 1 week ago

Executive Summary

UAC-0050 is a threat actor targeting government agencies in Ukraine since 2020. They use phishing campaigns with malware like Remcos RAT and have been linked to other hacking groups such as UAC-0096. Their primary tactic involves impersonating Ukrainian security services and distributing malicious attachments, likely for espionage purposes.

Goals & Targeting

UAC-0050's strategic objectives appear to center around intelligence gathering and espionage. Their targeting of Ukrainian government agencies suggests a focus on gaining access to sensitive information that could include diplomatic, military, or internal communications. By mimicking official security services and leveraging the trust of their targets, UAC-0050 can effectively compromise high-value systems. Their campaigns demonstrate a regional focus but may expand based on operational success and shared infrastructure with other groups.

Enhanced Description

UAC-0050 is an active cyber threat actor primarily targeting government agencies in Ukraine since first observed in 2020. The group is known to distribute Remcos Remote Access Trojan (RAT) malware through phishing campaigns that mimic legitimate communications from the Security Service of Ukraine. These operations often involve sending emails with malicious Office document attachments, leveraging social engineering tactics to gain initial access. UAC-0050 has also been linked to other hacking collectives, such as UAC-0096, and has demonstrated an ability to use remote administration tools like Remote Utilities. The group's activities are consistent with state-sponsored or politically motivated cyber espionage campaigns targeting critical government infrastructure in Ukraine. While their primary focus appears to be on Ukraine, there is potential for expansion due to the known links to other threat actors.

Key Capabilities

  • Phishing campaigns using malicious Office documents
  • Remcos RAT distribution
  • Social engineering tactics
  • Impersonation of state security services

MITRE ATT&CK Tactics

Reconnaissance
Resource Development
Initial Access
Defense Evasion

ATT&CK Techniques

T1059.003 - Email collection from compromised mailbox
T1078 - Valid accounts
T1490 - Content scraping from web servers
T1568.002 - Non-state affiliated cyber espionage

Software / Tooling

Remcos RAT
Remote Utilities
Phishing Email Templates

Campaigns & Victims

UAC-0050's campaigns typically involve a slow, persistent approach targeting specific sectors and countries. They have demonstrated the ability to maintain long-term access within targeted networks for espionage purposes. Notable operations include the distribution of Remcos RAT via phishing emails that impersonate the Security Service of Ukraine. The group's operational tempo appears to be synchronized with regional events, suggesting potential alignment with a state-sponsored agenda.

IOC Patterns

  • Phishing emails purporting to come from Ukrainian security services
  • Malicious Office document attachments in email campaigns
  • Use of Remcos RAT malware
  • Command and control (C2) infrastructure linked to known threat actors

Recommended Actions

  • Implement advanced phishing detection solutions to identify malicious email campaigns.
  • Monitor for suspicious activity in emails, especially from domains mimicking government services or security agencies.
  • Conduct regular user training on social engineering tactics and phishing awareness.
  • Apply network monitoring for indicators of Remcos RAT and related malware signatures.

Suggested Tags

Government targeting
State-sponsored espionage
Ukraine-focused

Confidence Assessment

The data provided is sufficient to identify UAC-0050 as a persistent cyber threat actor targeting Ukrainian government agencies. Their use of Remcos RAT and phishing tactics with social engineering elements aligns with known patterns for state-sponsored espionage groups. However, specific details such as exact motivations or the full scope of their capabilities remain unclear due to limited public reporting on UAC-0050.

ATT&CK Techniques

No techniques linked yet.

Software / Tooling

No tools linked yet.

Campaigns / Victims

No campaigns linked yet.

Observed Data

No observed data linked yet.

Indicators of Compromise

No IOCs linked yet.

References

No references recorded yet.

Intel Summary

0

Techniques

0

Tools

0

Campaigns

0

IOCs

0

Observed Data

0

Tactics

Tags

APT
Critical Infrastructure
Phishing
Backdoor / C2
Government Targeting
Government targeting
State-sponsored espionage
Ukraine-focused

Details

Type
Unknown
Confidence
60%
Added
May 17, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.