Scworld
Phishing Campaign Spoofs Ukrainian CERT to Deploy AGEWHEEZE RAT
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Between March 26 and 27, 2026, a phishing campaign targeted Ukrainian institutions, including government entities, healthcare providers, and educational institutions, by spoofing the Computer Emergency Response Team of Ukraine (CERT-UA). Attackers sent emails impersonating CERT-UA staff, urging recipients to download a password-protected ZIP file containing the AGEWHEEZE Remote Access Trojan (RAT). The phishing emails were accompanied by a counterfeit website, cert-ua[.]tech, which mimicked the official CERT-UA site. AGEWHEEZE provides attackers with extensive control over infected machines, including real-time input emulation and file system operations. CERT-UA reported that the campaign was largely unsuccessful, impacting only a limited number of personal devices. The malicious software was distributed via links to a file-sharing service and was designed to establish persistence on infected systems. The attack highlights ongoing cybersecurity threats faced by Ukraine amid its geopolitical situation.
Key Points: • Phishing emails impersonated CERT-UA to distribute AGEWHEEZE RAT. • The counterfeit website cert-ua[.]tech was created to support the attack. • The campaign primarily targeted government and healthcare sectors in Ukraine.