logo

GetSmoked: UAC-0006 Returns With SmokeLoader Targeting Ukraine's Largest State-Owned Bank

ID: a5e5260c-37c8-5a8d-a44c-e5e58f9c252d

STIX ID: report--a5e5260c-37c8-5a8d-a44c-e5e58f9c252d

Feed Name: CloudSEK Blog

Threat Score
75/100

Date Published: 2025-02-05

Date Updated: 2026-04-27

...
...

The report documents an active phishing campaign attributed to UAC-0006 targeting customers of Ukraine's largest bank (PrivatBank). Attackers distribute password-protected archives containing malicious JavaScript, VBScript, or LNK files that use encoded PowerShell, process injection, and mshta-based techniques to deliver SmokeLoader and contact C2 infrastructure; the report provides IOCs (hashes, URLs, IPs), YARA rules, MITRE mapping, mitigation guidance, and notes TTP overlap with FIN7.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.