New UAC-0247 Campaign Steals Browser and WhatsApp Data From Hospitals and Governments
ID: 8af61a5c-75ae-5151-a289-9c5521df2942
STIX ID: report--8af61a5c-75ae-5151-a289-9c5521df2942
Feed Name: cybersecurityNews.com
UAC-0247 has run an active 2026 campaign against Ukrainian local governments and healthcare, using deceptive emails that lead to fake or XSS-vulnerable sites which deliver archives containing LNK/HTA payloads; these deploy AGINGFLY (a C# RAT with on-the-fly compiled command handlers) plus credential stealers (CHROMELEVATOR, ZAPIXDESK), reconnaissance (RUSTSCAN), tunneling (LIGOLO-NG, CHISEL), and persistence mechanisms (scheduled tasks, SILENTLOOP PowerShell), resulting in data theft and lateral network compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
