logo

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

ID: 6db08e00-84a2-5308-a1b4-c240cfda1a33

STIX ID: report--6db08e00-84a2-5308-a1b4-c240cfda1a33

Feed Name: The Hacker News

Threat Score
50/100

Date Published: 2026-04-01

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CERT-UA disclosed a phishing campaign by actor(s) tracked as UAC-0255 / Cyber Serp that impersonated the agency to distribute a password-protected ZIP (CERT_UA_protection_tool.zip) containing AGEWHEEZE, a Go-based RAT that communicates over WebSockets (observed IP 54.36.237.92), supports extensive remote-control functions and persistence mechanisms; targets included state bodies, medical centers, security firms, education, financial and software companies, but the agency reported only a few infected personal devices and provided remediation assistance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.