UAC-0094 is known for targeting Telegram accounts through phishing and social engineering attacks.
Analyst brief
UAC-0094 is a threat actor tracked by Ukrainian state cyber authorities, focusing on compromising Telegram accounts. They target Telegram users by sending messages containing malicious links to the Telegram website to gain unauthorized access and intercept SMS-based one-time codes. Their key TTPs involve phishing messages and social engineering tactics. Defenders should be vigilant about suspicious Telegram messages, especially links from unknown senders, and reinforce the security of multi-factor authentication mechanisms.
UAC-0094
unknown
State Service of Special Communication and Information Protection of Ukraine spotted a new wave of cyber attacks aimed at gaining access to users’ Telegram accounts. The Ukrainian CERT attributes the hacking campaign to threat actors tracked as UAC-0094. Threat actors are targeting Telegram users by sending Telegram messages with malicious links to the Telegram website in order to gain unauthorized access to the records and transfer a one-time code from SMS.
Which platform's users are primarily targeted by the UAC-0094 threat actor?+
UAC-0094 primarily targets Telegram users.
What methods does UAC-0094 use to gain unauthorized access to accounts?+
UAC-0094 uses phishing messages and social engineering tactics, including sending malicious links to the Telegram website to intercept SMS-based one-time codes.