UAC-0102
- Primary motivation
- espionage
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- nation-state
- Profile updated
- 2026-07-07 12:16:47
Targeted industries: media-and-entertainment technology-and-telecommunications
Targeted regions: country_code:ua
Context
UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a fraudulent website to steal authentication data. Security teams can use Sigma rules to detect their phishing campaigns and leverage IOCs provided by CERT-UA to hunt for their activity in SIEM or EDR environments.
Reports & references
- socprime.com — Uac 0102 Phishing Attack Detection Hackers Steal Authentication Data Impersonating The Ukr Net Web Service (report)
- CERT-UA — 4928679 (report)