UAC-0200 is a Russian-attributed threat cluster that has been linked to cyber-espionage activity targeting Ukraine, including Ukrainian defense and military-related Windows systems. CERT-UA reported increased cyber-espionage activity against Ukraine involving UAC-0200, and broader reporting identified UAC-0200 as one of five Russian-attributed groups responsible for much of the activity against Ukrainian forces. The cluster has been associated with social-engineering campaigns that abuse messaging applications, particularly Signal, to deliver the DarkCrystal RAT (DCRat) remote access trojan. CERT-UA warned that attackers used compromised accounts and messenger-based lures to persuade victims to open malicious files on their computers. Reporting also states that DCRat, also known as Dark Crystal RAT, was created by a Russian developer and has previously been used against Ukraine by UAC-0200. Based on the provided content, UAC-0200 uses remote access trojans to compromise victim systems, with DCRat specifically associated with this cluster. The content links the group to espionage-oriented operations against Ukraine and to the broader Russian campaign focus on intelligence collection against Ukrainian military and defense targets. Known alias in the provided material: UAC-0200.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 malware family attributed to this actor across reporting.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Previously used DCRat in operations targeting Ukraine (as referenced in the content).
Referenced as part of an increase in cyber-espionage activity against Ukraine (no additional details provided in this content).
Russian-attributed threat group targeting Ukraine's defense and military sectors, primarily for intelligence gathering through cyber operations.
UAC-0200 is associated with campaigns exploiting the Signal app to deploy the DCRat trojan.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.