logo

UAC-0215 Phishing Campaign Targets Ukraine's Critical Sectors

ID: 5eb7429a-2eb9-590d-a6c8-ddf375c8d40f

STIX ID: report--5eb7429a-2eb9-590d-a6c8-ddf375c8d40f

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-10-29

Date Updated: 2026-07-17

...
...

CERT-UA attributes a phishing campaign to APT UAC-0215 that used malicious .rdp configuration files delivered via spoofed emails to target Ukrainian public authorities, major industries, and military units; when opened the .rdp files connect victims to attacker-controlled servers and expose local resources (disks, network shares, printers, COM ports, audio devices, clipboard), enabling unauthorized execution and further compromise. The campaign was first detected on 2024-10-22 with preparatory activity from August 2024, has been corroborated by multiple cybersecurity organizations, and the report recommends blocking .rdp attachments, restricting .rdp execution, firewall rules to prevent external mstsc.exe connections, and disabling RDP resource redirection.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.