UAC-0006 — APT Profile
UAC-0006 is a financially motivated threat actor that has been active since at least 2013. They primarily target Ukrainian organizations, particularly accountants, with phishing emails containing the SmokeLoader malware. Their goal is to steal credentials and execute unauthorized fund transfers, posing a significant risk to financial systems.Tools & malware
- win.smokeloader Loader
Vendor research
- Весняне загострення: UAC-0006 активізувало кібератаки CERT-UA
- Нарощування темпів UAC-0006, мільйонні збитки (CERT-UA#7648, CERT-UA#7688, CERT-UA#7699, CERT-UA#7705) CERT-UA
- From espionage to PsyOps: Tracking operations and bulletproof providers of UACs in 2025 Intrinsec
- Зведена інформація щодо діяльності угрупування UAC-0006 станом на 01.12.2023 CERT-UA
- Semi-Annual Chronicles of UAC-0006 Operations State Cyber Protection Centre, SSSCIP (Ukraine)