logo

UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign

ID: ed1490d7-6d57-5209-8cfe-fbe4bb22f945

STIX ID: report--ed1490d7-6d57-5209-8cfe-fbe4bb22f945

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-04-16

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

CERT‑UA reported a March–April 2026 campaign attributed to cluster UAC‑0247 that used phishing links (compromised or AI‑generated sites) to deliver LNK/HTA chains and multi‑stage loaders, deploying RAVENSHELL (TCP reverse shell), AGINGFLY (C# backdoor), and SILENTLOOP (PowerShell) to exfiltrate credentials and WhatsApp/Chromium data, establish tunnels, and enable lateral movement; multiple open‑source tools and DLL side‑loading were observed, and defenses recommended include restricting execution of LNK/HTA/JS and blocking utilities like mshta.exe and powershell.exe.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.