Fake CERT-UA Site Spreads Go-Based RAT in Phishing Campaign
ID: f736fb3a-39fd-52f1-9103-ef0cbd9ab1d6
STIX ID: report--f736fb3a-39fd-52f1-9103-ef0cbd9ab1d6
Feed Name: GBHackers
CERT-UA reported a targeted phishing campaign (Mar 26–27, 2026) that cloned the official CERT-UA site and distributed a Go-based RAT called AGEWHEEZE in password-protected archives hosted on Files.fm. The malware provides extensive remote-control capabilities, achieves persistence via APPDATA paths and scheduled tasks, and communicates with a C2 over WebSockets (54.36.237.92:8443); the campaign used the fraudulent domain cert-ua.tech and was linked to actor UAC-0255/Cyber Serp, though infections were limited and primarily affected personal devices of educational staff. CERT-UA recommended enforcing SRP/AppLocker, verifying downloads, blocking suspicious domains, and using endpoint protections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
