logo

From clinics to government: UAC-0247 expands cyber campaign across Ukraine

ID: a7c187f9-9380-572f-aade-4210908b5e35

STIX ID: report--a7c187f9-9380-572f-aade-4210908b5e35

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CERT-UA attributes a March–April 2026 campaign to UAC-0247 that targeted Ukrainian government bodies and municipal healthcare facilities using phishing (malicious LNK/HTA) to deploy multi-stage malware (including AGINGFLY, SILENTLOOP, CHROMELEVATOR, ZAPIXDESK) for browser and WhatsApp credential theft, remote control, lateral movement, and persistence via techniques such as scheduled tasks, DLL side‑loading, process injection, custom loaders, and encrypted C2 channels (Telegram, AES‑CBC websockets).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.