UAC-0215 is a likely APT group targeting Ukrainian state, industry, and military entities using rogue RDP files.
Analyst brief
UAC-0215 is a threat actor of unknown type, likely conducting APT operations, that targets public institutions, major industries, and military units in Ukraine. Their primary TTP involves a phishing campaign using rogue RDP files in malicious emails to gain unauthorized access to local system resources. Defenders should focus on blocking RDP files at email gateways, restricting RDP connection capabilities, and enhancing user awareness against suspicious attachments.
UAC-0215
unknown
UAC-0215 is an APT group that has orchestrated a phishing campaign targeting public institutions, major industries, and military units in Ukraine, utilizing rogue RDP files to gain unauthorized access. The malicious emails are designed to appear legitimate, enticing recipients to open attachments that connect their systems to the attacker's server, allowing extensive access to local resources. CERT-UA has identified this activity as high-risk and has advised organizations to block RDP files at mail gateways and restrict RDP connection capabilities. The campaign's geographical footprint suggests a potential for broader cyberattacks beyond Ukraine.