Skip to main content
Mallory
4 malware familiesExploits CVEs in the wild

UAC-0006

Also known asUAC-0006

UAC-0006 is a financially motivated threat actor tracked by CERT-UA and active since at least 2013. The group is closely associated with SmokeLoader and has repeatedly targeted Ukraine, including Ukrainian financial institutions and customers of PrivatBank. Reported activity includes phishing campaigns delivering SmokeLoader via password-protected archives, ZIP attachments, malicious VBS files, JavaScript, VBScript, LNK files, IMG files containing executables, and Microsoft Access .ACCDB documents with macros that launch PowerShell to download payloads. CERT-UA also reported campaigns in May 2024 distributing SmokeLoader, after which additional malware including TALESHOT and RMS was downloaded, with the botnet assessed to include several hundred infected computers. The actor’s operations are described as financially motivated, with CERT-UA warning of likely fraud involving remote banking systems. CERT-UA also states that at minimum UAC-0006 and UAC-0050 are involved in theft of funds from individuals and legal entities. In observed campaigns, UAC-0006 used compromised email accounts, invoice-themed and other business-themed phishing lures, and password-protected attachments to evade email security checks. Reported execution and post-compromise behavior includes PowerShell, process injection, use of legitimate system binaries, command-and-control communications, persistence via Run keys, firewall rule modification, and delivery of follow-on payloads. CERT-UA reporting also notes SmokeLoader variants capable of resolving current A records for configured domains via DNS queries. UAC-0006 has also been linked in reporting to exploitation of the 7-Zip vulnerability CVE-2025-0411 to deliver SmokeLoader against Ukrainian organizations. In that reporting, the campaign targeted Ukrainian government and private-sector entities and was assessed as likely cyber-espionage despite SmokeLoader’s long-standing use in financially motivated operations. Mentioned targets included Ukrainian state and financial institutions, major manufacturers, public services, and smaller local organizations that could serve as pivot points. Infrastructure and tradecraft directly mentioned in the content include use of Russian registrars such as reg.ru and nic.ru, Russian hosting including macloud.ru and cloudx.ru, and multiple .ru domains in SmokeLoader campaigns. One report states UAC-0006 TTPs overlap with FIN7, indicating possible ties to Russian APT activity, but the content does not establish that UAC-0006 is the same group as FIN7. Known related actor references in the content include UAC-0050 as another CERT-UA-tracked financially motivated group involved in theft activity. No additional confirmed aliases beyond UAC-0006 are provided in the content.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

MITRE ATT&CK

Tradecraft

13 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

7 of 15 tactics23 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1190
Exploit Public-Facing Application
T1566
Phishing
T1566.001
Spearphishing Attachment
TA0002
Execution
3 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1204
User Execution
T1204.002
Malicious File
TA0003
Persistence
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1053
Scheduled Task/Job
T1053.005
Scheduled Task
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
1 technique
T1027
Obfuscated Files or Information
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1071.001
Web Protocols
T1105
Ingress Tool Transfer
T1568
Dynamic Resolution
TA0040
Impact
1 technique
T1496
Resource Hijacking
WEAPONIZED

Associated vulnerabilities

1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.

ACTIVITY FEED

Recent activity

8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping13

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal4

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs1

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables

Domains, IPs, and hashes tied to this actor, refreshed continuously.