UAC-0102

Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 12:16:47

Targeted industries: media-and-entertainment technology-and-telecommunications

Targeted regions: country_code:ua

Context

UAC-0102 is a threat actor group targeting UKR.NET users through phishing attacks. They distribute emails with HTML file attachments that redirect users to a fraudulent website to steal authentication data. Security teams can use Sigma rules to detect their phishing campaigns and leverage IOCs provided by CERT-UA to hunt for their activity in SIEM or EDR environments.

Reports & references

  • socprime.com — Uac 0102 Phishing Attack Detection Hackers Steal Authentication Data Impersonating The Ukr Net Web Service (report)
  • CERT-UA — 4928679 (report)

External references