logo

Threat actor UAC-0255 impersonate CERT-UA to spread AGEWHEEZE malware via phishing

ID: fc939f00-72e7-5ba7-9e8d-8399521c8183

STIX ID: report--fc939f00-72e7-5ba7-9e8d-8399521c8183

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-04-02

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Threat actor UAC-0255 impersonated CERT-UA in a large phishing campaign delivering the AGEWHEEZE remote access trojan via password-protected archives hosted on Files.fm and a fake CERT-UA website (cert-ua.tech); AGEWHEEZE provides remote command execution, file and screen access, input control, persistence via registry/startup/scheduled tasks, and WebSocket-based C2. CERT-UA observed limited confirmed infections (a few educational institutions) and helped contain the campaign, while the actors claimed broader impact (unverified); indicators include archive names ("CERT_UA_protection_tool.zip", "protection_tool.zip"), internal package path ("/example.com/tvisor/agent"), and the fake domain cert-ua.tech with C2 hosted on OVH.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.