ThreatCluster

UAC-0247 Cyberattacks Target Hospitals and Governments in Ukraine

First seen 16 Apr 2026, 14:15 UTC CybersecuritynewsGbhackers 73

Article Content

Browse articles
ThreatCluster

A series of cyberattacks attributed to the UAC-0247 threat cluster has been detected, primarily targeting local governments and municipal healthcare institutions in Ukraine, including clinical hospitals and emergency ambulance services. The attacks began in early 2026 and involve sophisticated data theft methods, specifically targeting sensitive information from internet browsers and WhatsApp. The initial attack vector consists of phishing emails disguised as humanitarian aid proposals, which facilitate the attackers' access to the networks. The attackers are noted for their persistence and lateral movement capabilities within compromised networks. The scope of the impact is significant, affecting critical infrastructure and sensitive data of healthcare providers. As of April 16, 2026, the attacks are ongoing, with no reports of containment or remediation measures disclosed. The situation poses a serious risk to patient data and operational integrity of healthcare services in the affected regions.

Key Points: • UAC-0247 has been actively targeting Ukrainian healthcare and government sectors since early 2026. • Phishing emails disguised as humanitarian proposals are the primary attack vector. • The attackers are stealing data from browsers and WhatsApp, indicating a sophisticated operation.

Timeline

2026-01-01
UAC-0247 campaign begins targeting local governments and healthcare institutions.
2026-04-16
Gbhackers and Cybersecuritynews report on ongoing attacks.