CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
ID: 6db08e00-84a2-5308-a1b4-c240cfda1a33
STIX ID: report--6db08e00-84a2-5308-a1b4-c240cfda1a33
Feed Name: The Hacker News
CERT-UA disclosed a phishing campaign by actor(s) tracked as UAC-0255 / Cyber Serp that impersonated the agency to distribute a password-protected ZIP (CERT_UA_protection_tool.zip) containing AGEWHEEZE, a Go-based RAT that communicates over WebSockets (observed IP 54.36.237.92), supports extensive remote-control functions and persistence mechanisms; targets included state bodies, medical centers, security firms, education, financial and software companies, but the agency reported only a few infected personal devices and provided remediation assistance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
