Threats · 152 days ago
The real break is not the lure itself. It is that a simple email click can hand attackers browser sessions and WhatsApp content from clinics and government offices, then give them a path to move deeper inside the network. The standard response of treating this as just another phishing wave misses the data-theft and lateral-movement value of the payloads.
CERT-UA says the March–April 2026 campaign targeted Ukrainian clinics, emergency hospitals, municipal healthcare institutions, and government bodies. The chain used a humanitarian-aid lure, then LNK files and HTA execution through mshta.exe, with AGINGFLY among the payloads used to steal data from Chromium-based browsers and WhatsApp.
The lure quality also changed. CERT-UA says attackers used both XSS-compromised legitimate sites and AI-generated fake sites, which makes the delivery more believable and harder to filter by reputation alone.
1 source covering this story
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
CERT-UA reports UAC-0247 targeted clinics in March–April 2026, stealing browser and WhatsApp data, enabling lateral movement.
Part of the PlainSec briefing for 2026-04-17