logo

UAC-0247 Attack Detection: AGINGFLY Malware Targets Hospitals, Local Governments, and FPV Operators in Ukraine

ID: 7c21cb65-fe8e-5f88-83c4-f03c36afa4ad

STIX ID: report--7c21cb65-fe8e-5f88-83c4-f03c36afa4ad

Feed Name: SOC Prime Blog

Threat Score
75/100

Date Published: 2026-04-16

Date Updated: 2026-04-30

Author: SOC Prime Team

...
...

## Executive Summary CERT-UA observed a UAC-0247 phishing campaign leveraging humanitarian-themed lures and deceptive web delivery to push multi-stage loaders that ultimately deploy AGINGFLY and related tools (RAVENSHELL, SILENTLOOP). The operation abuses LNK/HTA execution (mshta.exe), shellcode injection, DLL side-loading, and credential-theft tooling to enable remote access, data exfiltration, and lateral movement against Ukrainian local government, healthcare, and likely defense-adjacent targets; CERT-UA recommends restricting risky file types and monitoring native Windows utilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.