UAC-0006 joint report, 2023: 27 chains catalogued, operators unnamed

What the Record Actually Is

The joint analytical report produced by Ukraine’s Cyber Incidents Response Operational Centre (CIROC, a unit within the State Cyber Protection Centre of Ukraine’s State Service of Special Communications and Information Protection, abbreviated SSSCIP) and Palo Alto Networks’ Unit 42 Threat Intelligence team carries a December 2023 publication date. The two bodies describe it explicitly as their first jointly produced analytical report. A second report on the same campaign, produced by Ukraine’s National Cybersecurity Coordination Centre under the National Security and Defense Council, is referenced in the document; the available source does not state when it was released.

The anomaly sits in the archival metadata. The version held at the National Security Archive carries a pipeline publication date of May 11, 2023, a date that falls before the earliest incident the document describes. The report’s own cover says December 2023. The record does not account for the discrepancy.

The Campaign as the Record Describes It

CERT-UA’s first alert for what would become a sustained, six-month series was issued on May 5, 2023. Alert CERT-UA#6613 documented the return of threat cluster UAC-0006 using accounting-themed phishing emails as the delivery vehicle. The documented waves continued through November 23, 2023, with CIROC and Unit 42 cataloging 23 distinct attack waves across that span.

The lure material remained consistent throughout: subject lines referenced invoices, reconciliation statements, payment requests, and billing documents, calibrated to the routine expectations of financial and clerical staff. August 2023 produced 198 phishing incidents attributed to the cluster; October 2023 produced 174. The CERT-UA#7648, #7688, #7699, and #7705 alerts adopted the phrase “loss of millions” to characterize the activity, though neither those alerts nor the joint report quantifies that figure.

The first documented wave, on May 10, 2023, used a polyglot ZIP archive (a single file structured to be read as two different file types) to deliver a JavaScript loader, which then executed a SmokeLoader payload. By May 29, 2023, the chain had grown an additional layer: a ZIP archive resolving to an HTML file, which released a second ZIP, which produced the JavaScript and then the executable. The basic delivery concept did not change across the period; the architecture around it did.

The Mechanics, as Cataloged

Across the 23 documented waves, CIROC and Unit 42 cataloged at least 27 distinct infection chain variants. The wave count and the variant count measure different things: a single wave could deploy more than one chain configuration, and the cluster demonstrably adjusted its technical architecture between, and sometimes within, individual waves. The 27-variant figure is the report’s tally of those distinct configurations, not a count of separate campaigns.

SmokeLoader is a downloader whose function is to pull additional malware onto a compromised machine. It has been available on criminal forums since 2011, marketed under the names Dofoil and Sharik as well. The report documents its evasion mechanisms: sandbox detection, obfuscated code built around opaque predicates (logical structures that always evaluate to the same result but are deliberately designed to defeat automated analysis), encrypted function blocks, anti-debugging routines, anti-hooking measures, and anti-virtual-machine checks.

The May 10, 2023 wave illustrates how those choices translated into execution. A PowerShell command retrieved an executable from a Russian-domain URL, placed it in a hidden folder within the user’s AppData directory, and ran it with three parameters: ExecutionPolicy Bypass (overriding any restrictions on script execution), NoProfile (loading without standard configuration files), and WindowStyle Hidden (suppressing any visible console window). Nothing in the user’s environment would signal that a download was underway.

One SmokeLoader sample analyzed from the campaign carried 14 command-and-control domains, 11 of which were active at the time of analysis, spanning .ru, .com, .site, .tech, .pro, .ug, and .org top-level domains, with registrars and hosting providers based in Russia. The monitoring authority under which Ukrainian organizations’ communications were tracked was Cabinet of Ministers Resolution No. 1295, dated December 23, 2020.

What the Investigators Concluded

CIROC and Unit 42 concluded that UAC-0006 was conducting a deliberate and continuously adapted campaign against Ukrainian financial and administrative organizations, using accounting-themed phishing as its consistent entry point and SmokeLoader as its consistent payload. CERT-UA ranked UAC-0006 first among financially motivated threat actors targeting Ukraine as of December 2023. The report characterizes the campaign’s goal as credential theft used in remote banking systems, enabling unauthorized payment transfers.

Two bodies of external analysis added their own characterizations. The Centre for Strategic Communication and Information Security assessed UAC-0006 as a Russia-based criminal group, assigning a probability they described as high, set at 70 to 89 percent. Unit 42’s report noted what it called potential connections to Russian cybercrime operations. Both are analytical assessments made by those bodies for their own published outputs; neither constitutes formal attribution by CERT-UA or any official investigative body, and the fact sheet marks them as claims rather than findings.

Where the Attribution Stops

UAC-0006 is a tracking label. CERT-UA assigns cluster designations to group observed behaviors consistent enough across time to treat as a single actor; the designation is not an identification of individuals, organizations, or sponsors. The report does not name a nation-state, a criminal organization, or an individual operator. As of the document’s December 2023 publication date, no official body had confirmed who operated the cluster. The evidence that might support deeper attribution, if it exists, is held in channels that do not appear in the public record.

What the Record Does Not Contain

The report documents delivery chains in technical detail but stops before post-infection activity. What secondary payloads SmokeLoader installed on successfully compromised machines is not stated in the available record.

The CERT-UA#7648, #7688, #7699, and #7705 alerts reference “loss of millions.” The joint CIROC/Unit 42 report does not quantify that figure, name affected organizations, or independently verify the characterization. A December 2023 analytical summary by SOC Prime, citing CERT-UA’s overview, estimated that attempted financial crimes may have reached the equivalent of one million Ukrainian hryvnias per week during peak periods; that is SOC Prime’s reading of the overview, not a confirmed total drawn from the primary record.

The parallel report produced by the National Cybersecurity Coordination Centre is referenced in the document, but the document does not state when it was released. Whether the two reports cover the same organizations, share underlying data, or were produced concurrently cannot be established from what is publicly available.