Skip to content
Phishing Campaign Spoofs Ukrainian CERT to Deploy AGEWHEEZE RAT

Phishing Campaign Spoofs Ukrainian CERT to Deploy AGEWHEEZE RAT

First seen 31 Mar 2026, 21:32 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 1, 2026 at 21:02 UTC

Between March 26 and 27, 2026, a phishing campaign targeted Ukrainian institutions, including government entities, healthcare providers, and educational institutions, by spoofing the Computer Emergency Response Team of Ukraine (CERT-UA). Attackers sent emails impersonating CERT-UA staff, urging recipients to download a password-protected ZIP file containing the AGEWHEEZE Remote Access Trojan (RAT). The phishing emails were accompanied by a counterfeit website, cert-ua[.]tech, which mimicked the official CERT-UA site. AGEWHEEZE provides attackers with extensive control over infected machines, including real-time input emulation and file system operations. CERT-UA reported that the campaign was largely unsuccessful, impacting only a limited number of personal devices. The malicious software was distributed via links to a file-sharing service and was designed to establish persistence on infected systems. The attack highlights ongoing cybersecurity threats faced by Ukraine amid its geopolitical situation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 177d ago How this analysis works

Timeline

2026-03-26
Phishing campaign begins targeting Ukrainian institutions.
2026-03-27
Counterfeit website cert-ua[.]tech created.
2026-03-30
CERT-UA discloses details of the phishing campaign.
2026-03-31
Scworld publishes brief on the phishing campaign.

More articles in this cluster (13)

Following this threat?

Track Agewheeze and Education in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed