UAC-0184 is a threat actor known for targeting the Ukrainian Armed Forces with Remcos RAT via military-themed social engineering.
Analyst brief
UAC-0184 is a threat actor targeting Ukrainian organizations, particularly those operating in Finland, with a focus on the Armed Forces of Ukraine. The group employs social engineering by impersonating military recruitment processes to deliver the Remcos RAT. Their main TTPs include the use of Remcos Remote Access Trojan, the IDAT Loader for payload delivery, and steganographic image files to conceal malicious code. Defenders should prioritize monitoring for suspicious image-based payloads, military-themed phishing emails, and anomalous network activity indicative of Remcos RAT C2 communications.
UAC-0184
unknown
UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks. They have been observed utilizing steganographic image files and the IDAT Loader to deliver the malware. The group has targeted the Armed Forces of Ukraine and impersonated military recruitment processes to infect systems with the Remcos RAT.