A Russian hacking group, tracked as UAC-0050, is targeting a European financial institution in a attack social engineering, possibly with the aim of gathering information or stealing financial data.

The group is also known as the DaVinci Group, while BlueVoyant tracks it as Mercenary Akula. The attack on the financial institution was observed earlier this month.
“ The attack spoofed a Ukrainian judicial domain to deliver an email containing a link to a remote access payload ,” researchers Patrick McHale and Joshua Green said . “ The target was a senior legal and political advisor involved in procurement, a role with knowledge of the institution’s operations and financial mechanisms .”
See also: Lazarus subgroup uses Medusa ransomware
The attack began with a spear-phishing email that used legalese to direct the recipient to download an archive file hosted on PixelDrain, a file sharing service used by the threat actor to bypass reputation-based security checks.
UAC-0050: Multi-layered infection chain attack
The ZIP file starts a multi-layered infection chain . Inside the ZIP file is a RAR archive containing a password-protected 7-Zip archive. This, in turn, contains an executable that appears as a PDF document using the trick of the double extension (*.pdf.exe).
See also: Russian group exploits weak Fortinet firewalls via AI

Running this file deploys an MSI installer for Remote Manipulator System (RMS), a Russian remote desktop software that allows remote control, desktop sharing, and file transfers.
“The use of such ‘living-off-the-land’ tools provides attackers with persistent, silent access, while often evading traditional antivirus detection,” the researchers noted.
The use of RMS aligns with previous techniques of UAC-0050, as the threat actor is known for software remote access like LiteManager and remote access trojans like RemcosRAT.
The Computer Emergency Response Team of Ukraine (CERT-UA) has characterized UAC-0050 as a group linked to Russian law enforcement and conducting data collection, money theft, and information and psychological operations under the name Fire Cells.
See also: Operation Olalampo: MuddyWater targets organizations with new malware

“This attack reflects Mercenary Akula’s well-established and recurring attack profile, while also offering a notable development,” BlueVoyant said. “First, their targeting was primarily focused on entities based in Ukraine, with accountants and finance employees being key targets. However, this incident suggests a potential investigation into institutions supporting Ukraine in Western Europe.”
The revelation comes as Ukraine revealed that Russian cyberattacks targeting the energy infrastructure are increasingly focused on gathering information to guide missile attacks, rather than directly disrupting operations.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Cybersecurity firm CrowdStrike expects Russian groups to continue conducting offensive operations aimed at gathering intelligence from Ukrainian targets and NATO member states.
