UAC-0050 is a cyber espionage group active since 2020, targeting government entities.
Analyst brief
UAC-0050 is a cyber threat actor active since 2020, primarily known for targeting government agencies with an espionage motive. Based on current data, this group is targeting entities in Germany, using phishing campaigns to distribute the Remcos RAT malware. Their TTPs include impersonating official institutions and sending emails with malicious attachments, alongside using tools like Remote Utilities. Defenders should focus on detecting Remcos RAT and other remote administration tool network traffic, and enhance email security filtering to block spoofed government-themed phishing lures.
UAC-0050
unknown
UAC-0050 is a threat actor that has been active since 2020, targeting government agencies in Ukraine. They have been distributing the Remcos RAT malware through phishing campaigns, using tactics such as impersonating the Security Service of Ukraine and sending emails with malicious attachments. The group has also been linked to other hacking collectives, such as UAC-0096, and has previously used remote administration tools like Remote Utilities. The motive behind their attacks is likely espionage.