Skip to content

Incidents attributed to:

UAC-0102

UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks.

UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a fraudulent website to steal authentication data. Security teams can use Sigma rules to detect their phishing campaigns and leverage IOCs provided by CERT-UA to hunt for their activity in SIEM or EDR environments.

References


Actor metadata imported from Malpedia (Fraunhofer FKIE).