logo

Sophisticated Phishing Campaign Targets Ukraine’s Largest Bank

ID: ad1c2215-fd3b-50a3-bf5b-1689fd85818e

STIX ID: report--ad1c2215-fd3b-50a3-bf5b-1689fd85818e

Feed Name: Infosecurity Magazine (News)

Threat Score
70/100

Date Published: 2025-02-05

Date Updated: 2026-04-22

...
...

CloudSEK has identified an active phishing campaign by financially motivated group UAC-0006 targeting PrivatBank customers. The campaign uses password-protected ZIP/RAR attachments that drop JavaScript/VBScript or LNK files which run PowerShell, perform process injection, and deploy SmokeLoader for C2, enabling credential theft and persistent access; recommended mitigations include blocking malicious indicators, user training, and incident response preparedness.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.