Scworld Phishing Campaign Spoofs Ukrainian CERT to Deploy AGEWHEEZE RAT
Article Content
- •Phishing emails impersonated CERT-UA to distribute AGEWHEEZE RAT.
- •The counterfeit website cert-ua[.]tech was created to support the attack.
- •The campaign primarily targeted government and healthcare sectors in Ukraine.
Between March 26 and 27, 2026, a phishing campaign targeted Ukrainian institutions, including government entities, healthcare providers, and educational institutions, by spoofing the Computer Emergency Response Team of Ukraine (CERT-UA). Attackers sent emails impersonating CERT-UA staff, urging recipients to download a password-protected ZIP file containing the AGEWHEEZE Remote Access Trojan (RAT). The phishing emails were accompanied by a counterfeit website, cert-ua[.]tech, which mimicked the official CERT-UA site. AGEWHEEZE provides attackers with extensive control over infected machines, including real-time input emulation and file system operations. CERT-UA reported that the campaign was largely unsuccessful, impacting only a limited number of personal devices. The malicious software was distributed via links to a file-sharing service and was designed to establish persistence on infected systems. The attack highlights ongoing cybersecurity threats faced by Ukraine amid its geopolitical situation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track Agewheeze and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2026-93425: Dokploy PaaS Critical RCE Leads to Container Root and Host Compromise TheHackerWire / 1d Telemetry Metric Intelligence Detail CVE Identifier CVE-2026-93425 CVSS Severity 9.9 CRITICAL Affected Target the Dokploy container Vulnerability Class Security Vulnerability Exploit Availability No Public PoC Indexed EPSS Threat Score Awaiting scoring CISA KEV Status Not Listed in CISA KEV Remediation Status Advisory / Mitigation In Review A critical command injection vulnerability, CVE-2026
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…