Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
15 malware families

UAC-0050

Also known asUAC-0050

UAC-0050 is a threat actor primarily targeting organizations and individuals in Ukraine. Multiple sources in the provided content describe it as a Russia-aligned or Russian-linked mercenary/cybercrime group; CERT-UA links it to Russian law-enforcement structures and states it has operated under the DaVinci Group and Fire Cells Group brands. BlueVoyant refers to the cluster as Mercenary Akula. CERT-UA states the group’s activity includes information theft/cyber-espionage, theft of funds, and information-psychological operations. The actor has repeatedly used phishing and social-engineering campaigns with Ukraine-themed lures, including spoofed messages from the Security Service of Ukraine, Ukrainian tax authorities, and legal/judicial themes. Reported delivery chains include encrypted or zipped PDFs containing URLs, compressed HTML attachments, password-protected archives, LNK/VBS/BAT-based chains, and links to remote payloads. Proofpoint states UAC-0050 frequently distributes encrypted PDFs with URLs leading to malware, and on 14 January 2025 observed zipped PDFs leading to installation of NetSupport using the license "XMLCTL." CERT-UA also linked the group to phishing campaigns distributing Remcos RAT and to campaigns using Remote Utilities software, later suggesting related activity tracked as UAC-0096 should be consolidated under UAC-0050. Tooling and payloads directly mentioned in the content include NetSupport RAT, Remcos RAT, Quasar RAT, Venom RAT, Remote Utilities, LiteManager, TEKTONITRMS, RMS (Remote Manipulator System), LummaStealer, MeduzaStealer, Xeno RAT, SectopRAT, MarsStealer, DarkTrackRAT, and suspected Lucky Volunteer. The actor has used legitimate remote administration/remote monitoring tools as well as commodity RATs and stealers to gain remote access, persistence, credential theft, and follow-on access. CERT-UA reported that during September-October 2024 the group used REMCOS and TEKTONITRMS to maintain unauthorized access to accountants’ computers and conducted at least 30 attempted thefts from Ukrainian companies and individual entrepreneurs by forging payments through remote banking systems. Targeting in the content is heavily Ukraine-focused, especially accountants, financial officers, government entities, and other Ukrainian organizations. BlueVoyant also reported a social-engineering attack attributed to UAC-0050 against an unnamed European financial institution involved in regional development and reconstruction initiatives, suggesting possible probing of Western European institutions supporting Ukraine. In that case, the actor used a legal-themed spear-phishing lure, spoofed a Ukrainian judicial domain, delivered a multi-stage archive chain via PixelDrain, and ultimately installed RMS. Tradecraft described in the content includes use of compromised email accounts, spoofed sender identities, remote access software, credential theft, forged banking payments, and information operations under the Fire Cells Group brand. CERT-UA states the group has conducted more than 15 campaigns in early 2024 and more than 15 cyberattacks during September-October 2024, and characterizes it as one of the most active threats against Ukraine.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics32 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566×2
Phishing
T1566.001×3
Spearphishing Attachment
T1566.002×4
Spearphishing Link
TA0002
Execution
3 techniques
T1059
Command and Scripting Interpreter
T1059.001×2
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1059.007
JavaScript
T1197
BITS Jobs
T1204×4
User Execution
T1204.002
Malicious File
TA0003
Persistence
3 techniques
T1078
Valid Accounts
T1197
BITS Jobs
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
6 techniques
T1027×2
Obfuscated Files or Information
T1027.003
Steganography
T1036
Masquerading
T1036.007
Double File Extension
T1078
Valid Accounts
T1140
Deobfuscate/Decode Files or Information
T1197
BITS Jobs
T1218
System Binary Proxy Execution
T1218.010
Regsvr32
T1218.011
Rundll32
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×4
Ingress Tool Transfer
T1219×3
Remote Access Tools
IOCS

Observables

94 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Feb 24, 2026
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware

Russia-aligned/associated mercenary cybercrime activity conducting spear-phishing and social engineering to deploy remote access tooling for intelligence collection and/or financial theft; historically focused on Ukrainian entities (notably accountants/financial officers) with apparent expansion to Western European institutions supporting Ukraine’s reconstruction efforts.

Read more
checkpoint research blogNews
Feb 23, 2026
2025: The Untold Stories of Check Point Research - Check Point Research

Ukraine-focused phishing using compromised email accounts and tax-authority lures to deliver an archive that installs a remote IT/support tool for unauthorized access.

Read more
checkpoint research blogNews
Feb 23, 2026
2025: The Untold Stories of Check Point Research - Check Point Research

Cluster associated with phishing in Ukraine using compromised email accounts and delivery of a remote IT/support tool for unauthorized access.

Read more
proofpoint threat insight blogNews
Oct 23, 2025
Proofpoint releases innovative detections for threat hunting: PDF Object Hashing

Targets Ukraine using email campaigns with encrypted PDF attachments that contain URLs; those URLs typically download a compressed JavaScript file which, when executed, installs the NetSupport RAT payload. Uses encrypted PDFs to hinder content extraction while retaining a consistent PDF object structure that can be fingerprinted for clustering/attribution.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping22

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal15

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables94

Domains, IPs, and hashes tied to this actor, refreshed continuously.