HomeCyber BalkansCERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

Published on

spot_img


 The Computer Emergency Response Team of Ukraine (CERT-UA) has reported a new phishing campaign where attackers impersonated CERT-UA to distribute a remote access trojan called AGEWHEEZE.

The campaign, attributed to threat group UAC-0255, involved phishing emails sent on March 26–27, 2026, containing a password-protected ZIP file disguised as a security tool. The archive downloaded malware that allows attackers to execute commands, manage files, capture screenshots, and maintain persistence on infected systems.

The campaign targeted government institutions, medical centers, financial institutions, educational organizations, security companies, and software development firms. Some phishing emails were sent from the address incidents@cert-ua[.]tech.

The malware communicates with a remote server via WebSockets and can maintain persistence through scheduled tasks, registry changes, or startup folder modifications.

Authorities reported that the campaign had limited success, affecting only a small number of personal devices. The operation has been linked to a group calling itself Cyber Serp, which also previously claimed responsibility for a breach of a Ukrainian cybersecurity company.

Reference: CERT IMPERSONATION 



Source link

Latest articles

New Storm Infostealer Remotely Decrypts Stolen Credentials

Surge in Risks from New Infostealer Malware: Varonis Reports on "Storm" In an alarming development...

Top 5 SOC-as-a-Service Providers and Evaluation Criteria

Understanding SOCaaS: A Comprehensive Overview Security Operations Center as a Service (SOCaaS) represents a transformative...

Hasbro Cyberattack: A Timeline, its Impact, and Industry Implications

Hasbro Faces Cyber Intrusion: A Comprehensive Analysis In late March 2026, the Rhode Island-based toy...

NCSC Issues Security Alert Regarding Hackers Targeting WhatsApp and Signal

The National Cyber Security Centre (NCSC) in the United Kingdom has raised concerns regarding...

More like this

New Storm Infostealer Remotely Decrypts Stolen Credentials

Surge in Risks from New Infostealer Malware: Varonis Reports on "Storm" In an alarming development...

Top 5 SOC-as-a-Service Providers and Evaluation Criteria

Understanding SOCaaS: A Comprehensive Overview Security Operations Center as a Service (SOCaaS) represents a transformative...

Hasbro Cyberattack: A Timeline, its Impact, and Industry Implications

Hasbro Faces Cyber Intrusion: A Comprehensive Analysis In late March 2026, the Rhode Island-based toy...