New AgingFly malware used in attacks on Ukraine govt, hospitals
ID: cb5263d5-b10a-5aaa-af16-ea933b06b648
STIX ID: report--cb5263d5-b10a-5aaa-af16-ea933b06b648
Feed Name: Bleeping Computer
AgingFly is a C# remote-access/infostealer observed by CERT‑UA in attacks against Ukrainian local governments, hospitals, and defense-related targets; infection begins with phishing that delivers an LNK/HTA-based staged loader which injects shellcode and deploys a multi-stage payload. Operators use ChromElevator and ZAPiDESK to harvest browser and WhatsApp credentials, employ tunneling tools (Ligolo‑ng, Chisel) and port scanners for reconnaissance, deliver dynamically compiled command handlers from C2 via WebSockets (AES‑CBC) and use PowerShell/Telegram for configuration and C2 discovery; CERT‑UA attributes the campaign to UAC‑0247 and recommends blocking LNK/HTA/JS and monitoring for related activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
