LIVE NEWS
  • FDA Commissioner Makary praises staff in speech
  • California Suspends Enforcement of Law Requiring VCs to Report Diversity Data
  • Record monthly rise in petrol and diesel prices, says RAC
  • How Dow Jones is Affecting the Market Today
  • Scientists open 40-year-old salmon and find a surprising sign of ocean recovery
  • Global super-rich may have hidden $3.55tn from tax officials, says Oxfam | Tax havens
  • If chaplains are ‘officers second,’ which staff corps officers are next?
  • Astronauts can face ‘nearly lethal doses’ of solar radiation — so why launch Artemis II during the sun’s peak of activity? Space scientist Patricia Reiff explains.
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • See More
    • Artificial Intelligence
    • Climate Risks
    • Defense
    • Healthcare Innovation
    • Science
    • Technology
    • World
Prime Reports
  • Home
  • Popular Now
  • Crypto
  • Cybersecurity
  • Economy
  • Geopolitics
  • Global Markets
  • Politics
  • Artificial Intelligence
  • Climate Risks
  • Defense
  • Healthcare Innovation
  • Science
  • Technology
  • World
Home»Cybersecurity»CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
Cybersecurity

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

primereportsBy primereportsApril 1, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
Share
Facebook Twitter LinkedIn Pinterest Email


Ravie LakshmananApr 01, 2026Email Security / Artificial Intelligence

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new phishing campaign in which the cybersecurity agency itself was impersonated to distribute a remote administration tool known as AGEWHEEZE.

As part of the attacks, the threat actors, tracked as UAC-0255, sent emails on March 26 and 27, 2026, posing as CERT-UA to distribute a password-protected ZIP archive hosted on Files.fm and urged recipients to install the “specialized software.”

The targets of the campaign included state organizations, medical centers, security companies, educational institutions, financial institutions, and software development companies. Some of the emails were sent from the email address “incidents@cert-ua[.]tech.”

Cybersecurity

The ZIP file (“CERT_UA_protection_tool.zip”) is designed to download malware packaged as security software from the agency. The malware, per CERT-UA, is a remote access trojan codenamed AGEWHEEZE. 

A Go-based malware, AGEWHEEZE communicates with an external server (“54.36.237[.]92”) over WebSockets and supports a wide range of commands to execute commands, perform file operations, modify the clipboard, emulate mouse and keyboard, take screenshots, and manage processes and services. It also creates persistence by using a scheduled task, modifying the Windows Registry, or adding itself to the Startup directory.

The attack is assessed to have been largely unsuccessful. “No more than a few infected personal devices belonging to employees of educational institutions of various forms of ownership were identified,” the agency said. “The team’s specialists provided the necessary methodological and practical assistance.”

An analysis of the bogus website “cert-ua[.]tech” has revealed that it was likely generated with assistance from artificial intelligence (AI) tools, with the HTML source code also including a comment: “С Любовью, КИБЕР СЕРП,” meaning “With Love, CYBER SERP.”

In posts on Telegram, Cyber Serp claims that they are “cyber-underground operatives from Ukraine.” The Telegram channel was created in November 2025 and has more than 700 subscribers.

Cybersecurity

The threat actor also said the phishing emails were sent to 1 million ukr[.]net mailboxes as part of the campaign, and that over 200,000 devices have been compromised. “We are not bandits – the average Ukrainian citizen will never suffer as a result of our actions,” it said in a post.

Last month, Cyber Serp took responsibility for an alleged breach of Ukrainian cybersecurity company Cipher, stating it obtained a complete dump of the servers, including a client database and source code for their line of CIPS products, among others.

In a statement on its website, Cipher acknowledged that attackers compromised the credentials of an employee at one of its technology companies but said its infrastructure was operating normally. The infected user had access to a single project, which did not contain sensitive data, it added.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleVisa launches new AI tools to manage the charge dispute process
Next Article Iran threat to 18 U.S. firms opens a new risk front for crypto
primereports
  • Website

Related Posts

Cybersecurity

Depthfirst Raises $80 Million in Series B Funding

April 1, 2026
Cybersecurity

Google fixes Chrome zero-day with in-the-wild exploit (CVE-2026-5281)

April 1, 2026
Cybersecurity

Attack on axios software developer tool threatens widespread compromises

March 31, 2026
Add A Comment
Leave A Reply Cancel Reply

Top Posts

Global Resources Outlook 2024 | UNEP

December 6, 20257 Views

The D Brief: DHS shutdown likely; US troops leave al-Tanf; CNO’s plea to industry; Crowded robot-boat market; And a bit more.

February 14, 20264 Views

German Chancellor Merz faces difficult mission to Israel – DW – 12/06/2025

December 6, 20254 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Latest Reviews

Subscribe to Updates

Get the latest tech news from FooBar about tech, design and biz.

PrimeReports.org
Independent global news, analysis & insights.

PrimeReports.org brings you in-depth coverage of geopolitics, markets, technology and risk – with context that helps you understand what really matters.

Editorially independent · Opinions are those of the authors and not investment advice.
Facebook X (Twitter) LinkedIn YouTube
Key Sections
  • World
  • Geopolitics
  • Popular Now
  • Artificial Intelligence
  • Cybersecurity
  • Crypto
All Categories
  • Artificial Intelligence
  • Climate Risks
  • Crypto
  • Cybersecurity
  • Defense
  • Economy
  • Geopolitics
  • Global Markets
  • Healthcare Innovation
  • Politics
  • Popular Now
  • Science
  • Technology
  • World
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer
  • Cookie Policy
  • DMCA / Copyright Notice
  • Editorial Policy

Sign up for Prime Reports Briefing – essential stories and analysis in your inbox.

By subscribing you agree to our Privacy Policy. You can opt out anytime.
Latest Stories
  • FDA Commissioner Makary praises staff in speech
  • California Suspends Enforcement of Law Requiring VCs to Report Diversity Data
  • Record monthly rise in petrol and diesel prices, says RAC
© 2026 PrimeReports.org. All rights reserved.
Privacy Terms Contact

Type above and press Enter to search. Press Esc to cancel.