UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
ID: ed1490d7-6d57-5209-8cfe-fbe4bb22f945
STIX ID: report--ed1490d7-6d57-5209-8cfe-fbe4bb22f945
Feed Name: The Hacker News
CERT‑UA reported a March–April 2026 campaign attributed to cluster UAC‑0247 that used phishing links (compromised or AI‑generated sites) to deliver LNK/HTA chains and multi‑stage loaders, deploying RAVENSHELL (TCP reverse shell), AGINGFLY (C# backdoor), and SILENTLOOP (PowerShell) to exfiltrate credentials and WhatsApp/Chromium data, establish tunnels, and enable lateral movement; multiple open‑source tools and DLL side‑loading were observed, and defenses recommended include restricting execution of LNK/HTA/JS and blocking utilities like mshta.exe and powershell.exe.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
