UAC-0247 Cyberattacks Target Hospitals and Governments in Ukraine
Article Content
- •UAC-0247 has been actively targeting Ukrainian healthcare and government sectors since early 2026.
- •Phishing emails disguised as humanitarian proposals are the primary attack vector.
- •The attackers are stealing data from browsers and WhatsApp, indicating a sophisticated operation.
A series of cyberattacks attributed to the UAC-0247 threat cluster has been detected, primarily targeting local governments and municipal healthcare institutions in Ukraine, including clinical hospitals and emergency ambulance services. The attacks began in early 2026 and involve sophisticated data theft methods, specifically targeting sensitive information from internet browsers and WhatsApp. The initial attack vector consists of phishing emails disguised as humanitarian aid proposals, which facilitate the attackers' access to the networks. The attackers are noted for their persistence and lateral movement capabilities within compromised networks. The scope of the impact is significant, affecting critical infrastructure and sensitive data of healthcare providers. As of April 16, 2026, the attacks are ongoing, with no reports of containment or remediation measures disclosed. The situation poses a serious risk to patient data and operational integrity of healthcare services in the affected regions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…