UAC-0247 Uses Fake Aid Lures to Steal Chat Data

The real break is not the lure itself. It is that a simple email click can hand attackers browser sessions and WhatsApp content from clinics and government offices, then give them a path to move deeper inside the network. The standard response of treating this as just another phishing wave misses the data-theft and lateral-movement value of the payloads. CERT-UA says the March–April 2026 campaign targeted Ukrainian clinics, emergency hospitals, municipal healthcare institutions, and government bodies. The chain used a humanitarian-aid lure, then LNK files and HTA execution through mshta.exe, with AGINGFLY among the payloads used to steal data from Chromium-based browsers and WhatsApp. The lure quality also changed. CERT-UA says attackers used both XSS-compromised legitimate sites and AI-generated fake sites, which makes the delivery more believable and harder to filter by reputation alone.

Part of the PlainSec briefing for 2026-04-17

Sources