Skip to main content
Mallory
14 malware families

UAC-0050

Also known asUAC-0050

UAC-0050 is a Ukraine-focused threat actor tracked by CERT-UA and others. The group is also referred to as DaVinci Group; BlueVoyant uses the cluster name Mercenary Akula. CERT-UA describes UAC-0050 as a mercenary group associated with Russian law-enforcement structures/agencies and reports that it has conducted cyber-espionage, theft of funds, and information-psychological operations under the Fire Cells Group brand. CERT-UA also reported that the group announced cessation of activity under the DaVinci Group brand shortly before Russia’s 2022 invasion. Targeting has primarily focused on organizations in Ukraine, including accountants, financial officers, enterprises, individual entrepreneurs, government entities, energy-sector organizations, and other Ukrainian organizations. Reporting also describes phishing against multiple organizations in Ukraine, including campaigns masquerading as Ukrainian tax authorities and the Security Service of Ukraine. BlueVoyant reported a social-engineering operation against an unnamed European financial institution involved in regional development and reconstruction initiatives, assessing this may indicate probing of Western European institutions that support Ukraine. Observed tradecraft centers on phishing and social engineering with legal, tax, court, and payment-document lures, often using archives, encrypted or zipped PDFs, LNK/VBS/BAT chains, and URLs leading to staged payload delivery. The actor has repeatedly used legitimate remote access and remote monitoring tools as payloads, including NetSupport RAT, Remote Utilities, Remote Manipulator System (RMS), LiteManager, REMCOS/Remcos RAT, TEKTONITRMS, and other RATs and stealers cited by CERT-UA such as QUASAR RAT, VENOM RAT, LUMMASTEALER, MEDUZASTEALER, XENORAT, SECTOPRAT, MARSSTEALER, and DARKTRACKRAT. Proofpoint observed UAC-0050 delivering zipped PDFs with URLs that ultimately installed NetSupport using the license name XMLCTL, and noted similar JavaScript-based delivery mechanisms and overlapping NetSupport configuration with ZPHP, while explicitly stating this overlap does not prove they are the same actor. CERT-UA also linked behavior from a Remcos RAT phishing campaign and a February attack using Remote Utilities, and suggested tracking UAC-0050 and UAC-0096 under a single identifier, UAC-0050, based on behavioral similarities. CERT-UA reported that during September-October 2024 UAC-0050 used unauthorized access to accountants’ computers and remote administration tools to conduct at least 30 attempted thefts from Ukrainian companies and individual entrepreneurs by forging payments through remote banking systems, with stolen funds often converted to cryptocurrency. CERT-UA further assessed UAC-0050 as the most active threat in Q1 2024, with at least 15 campaigns recorded by 22 February 2024.

Share:
Are they targeting you?

Know when an actor pivots toward your sector

Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.

OPERATIONAL PROFILE

Targeting

Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.

Where they target

Geographies tied to known operations.

  • 🇺🇦 Ukraine
MITRE ATT&CK

Tradecraft

19 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.

6 of 15 tactics28 techniques×N= number of intelligence reports citing this technique
MITRE ATT&CK
TA0001
Initial Access
2 techniques
T1078
Valid Accounts
T1566
Phishing
T1566.001×2
Spearphishing Attachment
T1566.002×3
Spearphishing Link
TA0002
Execution
2 techniques
T1059
Command and Scripting Interpreter
T1059.001
PowerShell
T1059.003
Windows Command Shell
T1059.005
Visual Basic
T1059.007
JavaScript
T1204×3
User Execution
TA0003
Persistence
2 techniques
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0004
Privilege Escalation
2 techniques
T1078
Valid Accounts
T1547
Boot or Logon Autostart Execution
T1547.001
Registry Run Keys / Startup Folder
TA0005
Stealth
5 techniques
T1027×2
Obfuscated Files or Information
T1027.003
Steganography
T1036
Masquerading
T1036.007
Double File Extension
T1078
Valid Accounts
T1140
Deobfuscate/Decode Files or Information
T1218
System Binary Proxy Execution
T1218.010
Regsvr32
T1218.011
Rundll32
TA0011
Command and Control
3 techniques
T1071
Application Layer Protocol
T1105×3
Ingress Tool Transfer
T1219×3
Remote Access Tools
IOCS

Observables

6 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.

IOC values are gated. View more in Mallory for domains, IPs, hashes, and other artifacts, or pipe them straight into your SIEM.

ACTIVITY FEED

Recent activity

10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.

the hacker newsNews
Feb 24, 2026
UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware

Russia-aligned/associated mercenary cybercrime activity conducting spear-phishing and social engineering to deploy remote access tooling for intelligence collection and/or financial theft; historically focused on Ukrainian entities (notably accountants/financial officers) with apparent expansion to Western European institutions supporting Ukraine’s reconstruction efforts.

Read more
checkpoint research blogNews
Feb 23, 2026
2025: The Untold Stories of Check Point Research - Check Point Research

Ukraine-focused phishing using compromised email accounts and tax-authority lures to deliver an archive that installs a remote IT/support tool for unauthorized access.

Read more
checkpoint research blogNews
Feb 23, 2026
2025: The Untold Stories of Check Point Research - Check Point Research

Cluster associated with phishing in Ukraine using compromised email accounts and delivery of a remote IT/support tool for unauthorized access.

Read more
proofpoint threat insight blogNews
Oct 23, 2025
Proofpoint releases innovative detections for threat hunting: PDF Object Hashing

Targets Ukraine using email campaigns with encrypted PDF attachments that contain URLs; those URLs typically download a compressed JavaScript file which, when executed, installs the NetSupport RAT payload. Uses encrypted PDFs to hinder content extraction while retaining a consistent PDF object structure that can be fingerprinted for clustering/attribution.

Read more
What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: sector and geo overlap with your footprint, the IOCs they’re burning right now, detection coverage, and what to do next.
Target overlap

Match sector + geo + tech-stack targeting against your real footprint.

Tradecraft mapping19

Every observed MITRE ATT&CK technique, grouped by tactic.

Malware arsenal14

Families this actor is known to deploy, with IOCs and behavior.

Exploited CVEs

CVEs this actor has used in known campaigns.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Observables6

Domains, IPs, and hashes tied to this actor, refreshed continuously.