UAC-0184

Primary motivation
espionage
Sophistication
intermediate
Resource level
team
Actor type
nation-state
Profile updated
2026-07-07 12:14:23

Targeted industries: defense-and-aerospace government-and-public-sector

Targeted regions: country_code:ua country_code:fi

Context

UAC-0184 is a threat actor targeting Ukrainian organizations in Finland, using the Remcos Remote Access Trojan in their attacks. They have been observed utilizing steganographic image files and the IDAT Loader to deliver the malware. The group has targeted the Armed Forces of Ukraine and impersonated military recruitment processes to infect systems with the Remcos RAT.

Reports & references

  • blog.morphisec.com — Unveiling Uac 0184 The Remcos Rat Steganography Saga (report)
  • CERT-UA — 6276988 (report)

External references