UAC-0102 is a threat group known for phishing campaigns targeting UKR.NET user credentials.
Analyst brief
UAC-0102 is a threat group that conducts phishing attacks to steal authentication data from UKR.NET users. They distribute emails with HTML file attachments that redirect victims to a fraudulent website. Defenders should use Sigma rules to detect the phishing campaigns and hunt for IOCs provided by CERT-UA in their SIEM or EDR environments.
UAC-0102
unknown
UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a fraudulent website to steal authentication data. Security teams can use Sigma rules to detect their phishing campaigns and leverage IOCs provided by CERT-UA to hunt for their activity in SIEM or EDR environments.