HomeCyber BalkansCERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

Published on

spot_img


 The Computer Emergency Response Team of Ukraine (CERT-UA) has reported a new phishing campaign where attackers impersonated CERT-UA to distribute a remote access trojan called AGEWHEEZE.

The campaign, attributed to threat group UAC-0255, involved phishing emails sent on March 26–27, 2026, containing a password-protected ZIP file disguised as a security tool. The archive downloaded malware that allows attackers to execute commands, manage files, capture screenshots, and maintain persistence on infected systems.

The campaign targeted government institutions, medical centers, financial institutions, educational organizations, security companies, and software development firms. Some phishing emails were sent from the address incidents@cert-ua[.]tech.

The malware communicates with a remote server via WebSockets and can maintain persistence through scheduled tasks, registry changes, or startup folder modifications.

Authorities reported that the campaign had limited success, affecting only a small number of personal devices. The operation has been linked to a group calling itself Cyber Serp, which also previously claimed responsibility for a breach of a Ukrainian cybersecurity company.

Reference: CERT IMPERSONATION 



Source link

Latest articles

UAC-0247 Targets Hospitals and Governments with Browser and WhatsApp Data Theft

Surge of Cyberattacks Targeting Local Governments and Healthcare Institutions In recent weeks, a significant uptick...

The Ongoing Debate Over CISO Reporting Lines and Its Implications for Cybersecurity Leadership

In the ever-evolving landscape of cybersecurity, the dynamics between Chief Information Officers (CIOs) and...

Stryker Hack Impacts First Quarter Results

Stryker Fails to Secure Cyber Insurance Amid Major Data Breach In a significant development within...

How to Respond When Your AI Guardrails Fail

A Bug Unveils Flaws in AI Governance: A Call for Structural Change In recent developments,...

More like this

UAC-0247 Targets Hospitals and Governments with Browser and WhatsApp Data Theft

Surge of Cyberattacks Targeting Local Governments and Healthcare Institutions In recent weeks, a significant uptick...

The Ongoing Debate Over CISO Reporting Lines and Its Implications for Cybersecurity Leadership

In the ever-evolving landscape of cybersecurity, the dynamics between Chief Information Officers (CIOs) and...

Stryker Hack Impacts First Quarter Results

Stryker Fails to Secure Cyber Insurance Amid Major Data Breach In a significant development within...