Mass CERT-UA Impersonation Sends AGEWHEEZE RAT via Password-Protected ZIP

Threat actor UAC-0255 sent about 1 million phishing emails impersonating Ukraine's CERT-UA on March 26–27, 2026. The emails contained password-protected ZIP files hosted on Files.fm, bypassing email scanning. The ZIP dropped AGEWHEEZE, a Go-based remote access trojan communicating over WebSockets to 54.36.237.92. AGEWHEEZE supports extensive remote control and persistence mechanisms. Despite the volume, infections were limited to a few personal devices in educational institutions, suggesting either poor attacker tradecraft or effective defenses. Detection should focus on network indicators like Files.fm download activity and WebSocket connections to the C2 server, as payload scanning may miss the password-protected archive contents. This campaign highlights the need to hunt beyond mailbox heuristics and endpoint scans in sectors including government, healthcare, finance, education, and software development.

Part of the PlainSec briefing for 2026-04-02

Sources