logo

Ukrainian emergency services and hospitals hit by espionage campaign using new AgingFly malware

ID: 5a089995-78b0-52ab-8834-fe83b108f072

STIX ID: report--5a089995-78b0-52ab-8834-fe83b108f072

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-05-01

...
...

Researchers and CERT-UA observed an active espionage campaign by a group tracked as UAC-0247 that used phishing lures and malicious archives to deliver multiple malware tools (AgingFly, SilentLoop, ChromeElevator, ZapixDesk) against Ukrainian hospitals, local government and emergency services to achieve remote access, credential theft, data collection and in some cases to mine cryptocurrency; the report also notes a separate Russia-linked APT28 campaign targeting prosecutors and investigators in Ukraine and neighboring countries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.