UAC-0050
UAC-0050 is a threat actor primarily targeting organizations and individuals in Ukraine. Multiple sources in the provided content describe it as a Russia-aligned or Russian-linked mercenary/cybercrime group; CERT-UA links it to Russian law-enforcement structures and states it has operated under the DaVinci Group and Fire Cells Group brands. BlueVoyant refers to the cluster as Mercenary Akula. CERT-UA states the group’s activity includes information theft/cyber-espionage, theft of funds, and information-psychological operations. The actor has repeatedly used phishing and social-engineering campaigns with Ukraine-themed lures, including spoofed messages from the Security Service of Ukraine, Ukrainian tax authorities, and legal/judicial themes. Reported delivery chains include encrypted or zipped PDFs containing URLs, compressed HTML attachments, password-protected archives, LNK/VBS/BAT-based chains, and links to remote payloads. Proofpoint states UAC-0050 frequently distributes encrypted PDFs with URLs leading to malware, and on 14 January 2025 observed zipped PDFs leading to installation of NetSupport using the license "XMLCTL." CERT-UA also linked the group to phishing campaigns distributing Remcos RAT and to campaigns using Remote Utilities software, later suggesting related activity tracked as UAC-0096 should be consolidated under UAC-0050. Tooling and payloads directly mentioned in the content include NetSupport RAT, Remcos RAT, Quasar RAT, Venom RAT, Remote Utilities, LiteManager, TEKTONITRMS, RMS (Remote Manipulator System), LummaStealer, MeduzaStealer, Xeno RAT, SectopRAT, MarsStealer, DarkTrackRAT, and suspected Lucky Volunteer. The actor has used legitimate remote administration/remote monitoring tools as well as commodity RATs and stealers to gain remote access, persistence, credential theft, and follow-on access. CERT-UA reported that during September-October 2024 the group used REMCOS and TEKTONITRMS to maintain unauthorized access to accountants’ computers and conducted at least 30 attempted thefts from Ukrainian companies and individual entrepreneurs by forging payments through remote banking systems. Targeting in the content is heavily Ukraine-focused, especially accountants, financial officers, government entities, and other Ukrainian organizations. BlueVoyant also reported a social-engineering attack attributed to UAC-0050 against an unnamed European financial institution involved in regional development and reconstruction initiatives, suggesting possible probing of Western European institutions supporting Ukraine. In that case, the actor used a legal-themed spear-phishing lure, spoofed a Ukrainian judicial domain, delivered a multi-stage archive chain via PixelDrain, and ultimately installed RMS. Tradecraft described in the content includes use of compromised email accounts, spoofed sender identities, remote access software, credential theft, forged banking payments, and information operations under the Fire Cells Group brand. CERT-UA states the group has conducted more than 15 campaigns in early 2024 and more than 15 cyberattacks during September-October 2024, and characterizes it as one of the most active threats against Ukraine.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
22 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
15 malware families attributed to this actor across reporting.
10 additional families tracked in Mallory.
Observables
94 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned/associated mercenary cybercrime activity conducting spear-phishing and social engineering to deploy remote access tooling for intelligence collection and/or financial theft; historically focused on Ukrainian entities (notably accountants/financial officers) with apparent expansion to Western European institutions supporting Ukraine’s reconstruction efforts.
Ukraine-focused phishing using compromised email accounts and tax-authority lures to deliver an archive that installs a remote IT/support tool for unauthorized access.
Cluster associated with phishing in Ukraine using compromised email accounts and delivery of a remote IT/support tool for unauthorized access.
Targets Ukraine using email campaigns with encrypted PDF attachments that contain URLs; those URLs typically download a compressed JavaScript file which, when executed, installs the NetSupport RAT payload. Uses encrypted PDFs to hinder content extraction while retaining a consistent PDF object structure that can be fingerprinted for clustering/attribution.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.