logo

Hackers Clone CERT-UA Site to Trick Victims Into Installing Go-Based RAT

ID: 92908540-7fd5-5ec3-94dd-e254f9c1947f

STIX ID: report--92908540-7fd5-5ec3-94dd-e254f9c1947f

Feed Name: cybersecurityNews.com

Threat Score
65/100

Date Published: 2026-04-02

Date Updated: 2026-05-05

Author: Tushar Subhra Dutta

...
...

A phishing campaign tracked as UAC-0255 impersonated Ukraine’s CERT-UA by cloning the official site (cert.gov.ua) at cert-ua.tech and sending emails that urged recipients to download password-protected archives containing AGEWHEEZE, a Go-based remote access trojan; the malware installs in user AppData, creates registry Run entries and scheduled tasks (SvcHelper/CoreService) for persistence, and connects to C2 at 54.36.237.92 over WebSockets on port 8443. Investigators found domain and SSL artifacts, a Telegram channel claim by the actor calling themselves CYBER SERP, and limited infections mostly on personal devices at educational institutions before rapid takedown and remediation limited spread.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.