logo

UAC-0255 Attack Detection: Threat Actors Impersonate CERT-UA to Infect Ukrainian Public and Private Sector Organizations With AGEWHEEZE RAT

ID: d8359b9e-910b-523b-a602-f4b017768466

STIX ID: report--d8359b9e-910b-523b-a602-f4b017768466

Feed Name: SOC Prime Blog

Threat Score
60/100

Date Published: 2026-04-01

Date Updated: 2026-04-30

Author: Daryna Olyniychuk

...
...

Phishing campaign UAC-0255 (late March 2026) impersonated CERT-UA to push AGEWHEEZE, a Go-based RAT, via Files.fm-hosted password-protected archives and a fraudulent cert-ua.tech site; C2 infrastructure was observed on OVH and the CyberSerp Telegram channel claimed responsibility. Targeting spanned public and private sector organizations across Ukraine, but CERT-UA assessed the campaign as largely unsuccessful with only a few personal-device infections and provided mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.