logo

UAC-0247 Hits Hospitals, Governments With Browser and WhatsApp Data Theft

ID: d7bbf8a7-e4ef-575e-aafd-d36d67ea87bf

STIX ID: report--d7bbf8a7-e4ef-575e-aafd-d36d67ea87bf

Feed Name: GBHackers

Threat Score
85/100

Date Published: 2026-04-16

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

### Executive Summary The report describes a sophisticated, active campaign by UAC-0247 targeting Ukrainian municipal governments and healthcare facilities via phishing and malicious LNK/HTA loaders that execute mshta-based HTA scripts to deploy a two-stage payload: an encrypted TCP reverse shell (RAVENSHELL) followed by a C# RAT (AGINGFLY) capable of remote control, data theft (browser and WhatsApp via CHROMELEVATOR and ZAPIXDESK), and dynamic runtime command compilation; CERT-UA recommends restricting LNK/HTA/JS execution and administrative scripting utilities to mitigate the threat.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.