UAC-0006

First seen
2013-01-01 00:00:00
Primary motivation
financial-gain
Sophistication
intermediate
Resource level
organization
Actor type
criminal
Profile updated
2026-07-07 12:09:31

Targeted industries: financial-services government-and-public-sector

Targeted regions: country_code:ua

Context

UAC-0006 is a financially motivated threat actor that has been active since at least 2013. They primarily target Ukrainian organizations, particularly accountants, with phishing emails containing the SmokeLoader malware. Their goal is to steal credentials and execute unauthorized fund transfers, posing a significant risk to financial systems.

Reports & references

  • socprime.com — Smokeloader Detection Uac 0006 Group Launches A New Phishing Campaign Against Ukraine (report)
  • socprime.com — Smokeloader Malware Detection Uac 0006 Hackers Launch A Wave Of Phishing Attacks Against Ukraine Targeting Accountants (report)
  • socprime.com — Detecting Smokeloader Campaign Uac 0006 Keep Targeting Ukrainian Financial Institutions In A Series Of Phishing Attacks (report)
  • socprime.com — Detect Smokeloader Malware Uac 0006 Strikes Again To Target Ukraine In A Series Of Phishing Attacks (report)
  • socprime.com — Smokeloader Malware Detection Uac 0006 Group Reemerges To Launch Phishing Attacks Against Ukraine Using Financial Subject Lures (report)
  • CERT-UA — 4555802 (report)
  • CERT-UA — 6123309 (report)

External references