SYMBOLCOMMON_NAMEaka. SYNONYMS

UAC-0215  (Back to overview)


UAC-0215 is an APT group that has orchestrated a phishing campaign targeting public institutions, major industries, and military units in Ukraine, utilizing rogue RDP files to gain unauthorized access. The malicious emails are designed to appear legitimate, enticing recipients to open attachments that connect their systems to the attacker's server, allowing extensive access to local resources. CERT-UA has identified this activity as high-risk and has advised organizations to block RDP files at mail gateways and restrict RDP connection capabilities. The campaign's geographical footprint suggests a potential for broader cyberattacks beyond Ukraine.


Associated Families

There are currently no families associated with this actor.


References
2024-10-29cybleCyble
Phishing Campaign Targeting Ukraine: UAC-0215 Threatens National Security
UAC-0215
2024-10-24Cert-UACert-UA
Accounts in service UAC-0218: file theft using HOMESTEEL (CERT-UA#11717)
HOMESTEEL UAC-0215

Credits: MISP Project