logo

Bulletproof Hosting Fuels Russia-Linked Intrusion Sets’ Global Cyber Campaign

ID: db414e9b-8da3-5b53-aa10-9147692dfa7f

STIX ID: report--db414e9b-8da3-5b53-aa10-9147692dfa7f

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: do son

...
...

Intrinsec reports that Russia-aligned intrusion sets UAC-0050 and UAC-0006 ran global spam campaigns in Jan–Feb 2025 targeting Ukraine and allies, blending financial theft, espionage, and psychological operations; UAC-0050 focused on financial theft and disruptive psyops (including fake bomb threats and threats against public officials), while UAC-0006 targeted accountants with SmokeLoader. The campaigns used multiple malware families and phishing lures, exploited a 7‑Zip zero-day (CVE‑2025‑0411), and relied on bulletproof hosting and offshore shell companies tied to ransomware affiliates, illustrating a convergence of cybercrime and state-aligned operations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.