UAC-0247 Targets Hospitals and Governments In Browser and WhatsApp Data Theft Campaign
ID: 254a6d7e-b320-5811-b355-8b1db2a76540
STIX ID: report--254a6d7e-b320-5811-b355-8b1db2a76540
Feed Name: Cyber Press
CERT‑UA reports that the UAC-0247 group conducted a widespread March–April 2026 campaign against municipal governments, healthcare institutions (including clinical and emergency hospitals) and Ukrainian Defense Forces, using phishing lures, XSS-compromised or AI-generated fake sites to deliver LNK→HTA chains that install executables via scheduled tasks and inject shellcode into legitimate processes; attackers deploy custom credential- and chat-data theft tools (CHROMELEVATOR, ZAPIXDESK), perform network reconnaissance and tunneling (RUSTSCAN, LIGOLO-NG, CHISEL), and in some cases install modified WIREGUARD with an XMRIG miner and AGINGFLY backdoor via DLL side-loading, with recommended mitigations including restricting dangerous file execution, blocking abused system utilities, monitoring anomalous network connections, and endpoint detection for DLL side-loading and credential dumping.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
