logo

Hackers Impersonate Ukrainian CERT to Plant a RAT on Government, Hospital Networks

ID: 0be88b4f-5e34-5276-8e7d-b557dc6854ab

STIX ID: report--0be88b4f-5e34-5276-8e7d-b557dc6854ab

Feed Name: The Cyber Express

Threat Score
60/100

Date Published: 2026-03-30

Date Updated: 2026-04-23

Author: Mihir Bagwe

...
...

A March 26–27 phishing campaign impersonated Ukraine’s CERT-UA, hosting a convincing fake site and distributing password-protected archives that installed AGEWHEEZE, a Go-written Remote Access Trojan. The RAT offers extensive remote-control and persistence mechanisms, communicates over WebSocket to OVH-hosted C2 infrastructure (port 8443), and was publicly claimed by the CyberSerp Telegram channel; CERT-UA labeled the campaign largely unsuccessful with only a few personal devices infected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.