UAC-0050
UAC-0050 is a Ukraine-focused threat actor tracked by CERT-UA and others. The group is also referred to as DaVinci Group; BlueVoyant uses the cluster name Mercenary Akula. CERT-UA describes UAC-0050 as a mercenary group associated with Russian law-enforcement structures/agencies and reports that it has conducted cyber-espionage, theft of funds, and information-psychological operations under the Fire Cells Group brand. CERT-UA also reported that the group announced cessation of activity under the DaVinci Group brand shortly before Russia’s 2022 invasion. Targeting has primarily focused on organizations in Ukraine, including accountants, financial officers, enterprises, individual entrepreneurs, government entities, energy-sector organizations, and other Ukrainian organizations. Reporting also describes phishing against multiple organizations in Ukraine, including campaigns masquerading as Ukrainian tax authorities and the Security Service of Ukraine. BlueVoyant reported a social-engineering operation against an unnamed European financial institution involved in regional development and reconstruction initiatives, assessing this may indicate probing of Western European institutions that support Ukraine. Observed tradecraft centers on phishing and social engineering with legal, tax, court, and payment-document lures, often using archives, encrypted or zipped PDFs, LNK/VBS/BAT chains, and URLs leading to staged payload delivery. The actor has repeatedly used legitimate remote access and remote monitoring tools as payloads, including NetSupport RAT, Remote Utilities, Remote Manipulator System (RMS), LiteManager, REMCOS/Remcos RAT, TEKTONITRMS, and other RATs and stealers cited by CERT-UA such as QUASAR RAT, VENOM RAT, LUMMASTEALER, MEDUZASTEALER, XENORAT, SECTOPRAT, MARSSTEALER, and DARKTRACKRAT. Proofpoint observed UAC-0050 delivering zipped PDFs with URLs that ultimately installed NetSupport using the license name XMLCTL, and noted similar JavaScript-based delivery mechanisms and overlapping NetSupport configuration with ZPHP, while explicitly stating this overlap does not prove they are the same actor. CERT-UA also linked behavior from a Remcos RAT phishing campaign and a February attack using Remote Utilities, and suggested tracking UAC-0050 and UAC-0096 under a single identifier, UAC-0050, based on behavioral similarities. CERT-UA reported that during September-October 2024 UAC-0050 used unauthorized access to accountants’ computers and remote administration tools to conduct at least 30 attempted thefts from Ukrainian companies and individual entrepreneurs by forging payments through remote banking systems, with stolen funds often converted to cryptocurrency. CERT-UA further assessed UAC-0050 as the most active threat in Q1 2024, with at least 15 campaigns recorded by 22 February 2024.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Targeting
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Where they target
Geographies tied to known operations.
- 🇺🇦 Ukraine
Tradecraft
19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
14 malware families attributed to this actor across reporting.
9 additional families tracked in Mallory.
Observables
6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Russia-aligned/associated mercenary cybercrime activity conducting spear-phishing and social engineering to deploy remote access tooling for intelligence collection and/or financial theft; historically focused on Ukrainian entities (notably accountants/financial officers) with apparent expansion to Western European institutions supporting Ukraine’s reconstruction efforts.
Ukraine-focused phishing using compromised email accounts and tax-authority lures to deliver an archive that installs a remote IT/support tool for unauthorized access.
Cluster associated with phishing in Ukraine using compromised email accounts and delivery of a remote IT/support tool for unauthorized access.
Targets Ukraine using email campaigns with encrypted PDF attachments that contain URLs; those URLs typically download a compressed JavaScript file which, when executed, installs the NetSupport RAT payload. Uses encrypted PDFs to hinder content extraction while retaining a consistent PDF object structure that can be fingerprinted for clustering/attribution.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.