logo

UAC-0050 Targets European Financial Institution With Spoofed Domain and RMS Malware

ID: 5503eca9-60fe-5765-bfa4-9feb0317b9b7

STIX ID: report--5503eca9-60fe-5765-bfa4-9feb0317b9b7

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2026-02-24

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A Russia-aligned threat actor tracked as UAC-0050 (DaVinci Group / Mercenary Akula) conducted a spear-phishing operation against a European financial institution, using a layered ZIP/RAR/7z archive delivered via PixelDrain that installed an MSI for the Remote Manipulator System (RMS) RAT; the intrusion appears aimed at intelligence collection and financial theft and may represent an expansion of the group's targeting beyond Ukraine.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.