UAC-0200 is a Russian-attributed threat cluster involved in cyber-espionage operations against Ukraine, particularly Ukrainian military and defense-related targets. The cluster has been identified among the principal Russian-aligned groups conducting intelligence-gathering intrusions against Ukrainian forces and defense-sector organizations, with activity increasing during 2024 and 2025. UAC-0200 is associated with the use of remote access trojans, most notably DarkCrystal RAT (DCRat). The cluster has used social engineering through messaging platforms, including Signal, to induce victims to open malicious files on Windows systems. Reported operations rely on messenger-based phishing and compromised accounts to deliver malware, consistent with broader Russian targeting of Ukrainian military personnel and government-related entities. The group’s observed tradecraft supports initial access through phishing and social engineering, followed by persistent remote access and post-compromise collection. Because UAC-0200 is linked to DCRat operations, its activity is associated with capabilities such as keylogging, persistence, and broader post-exploitation on infected hosts. UAC-0200 appears to operate primarily for espionage, aligning with Russian intelligence-collection priorities in the war against Ukraine.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used DCRat in operations targeting Ukraine (as referenced in the content).
Referenced as part of an increase in cyber-espionage activity against Ukraine (no additional details provided in this content).
Russian-attributed threat group targeting Ukraine's defense and military sectors, primarily for intelligence gathering through cyber operations.
UAC-0200 is associated with campaigns exploiting the Signal app to deploy the DCRat trojan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.