UAC-0218 group is behind phishing attacks using HOMESTEEL malware for file theft.SOC Prime Platform has published Sigma rules for UAC-0218 activity detection.The phishing emails contain invoice-related subject lures leading to malicious RAR archives.The malware facilitates exfiltration of files to an adversary server via HTTP requests.