Threat actor UAC-0255 impersonate CERT-UA to spread AGEWHEEZE malware via phishing
ID: fc939f00-72e7-5ba7-9e8d-8399521c8183
STIX ID: report--fc939f00-72e7-5ba7-9e8d-8399521c8183
Feed Name: Security Affairs
Threat actor UAC-0255 impersonated CERT-UA in a large phishing campaign delivering the AGEWHEEZE remote access trojan via password-protected archives hosted on Files.fm and a fake CERT-UA website (cert-ua.tech); AGEWHEEZE provides remote command execution, file and screen access, input control, persistence via registry/startup/scheduled tasks, and WebSocket-based C2. CERT-UA observed limited confirmed infections (a few educational institutions) and helped contain the campaign, while the actors claimed broader impact (unverified); indicators include archive names ("CERT_UA_protection_tool.zip", "protection_tool.zip"), internal package path ("/example.com/tvisor/agent"), and the fake domain cert-ua.tech with C2 hosted on OVH.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
