Threats · 166 days ago
Threat actor UAC-0255 sent about 1 million phishing emails impersonating Ukraine's CERT-UA on March 26–27, 2026. The emails contained password-protected ZIP files hosted on Files.fm, bypassing email scanning. The ZIP dropped AGEWHEEZE, a Go-based remote access trojan communicating over WebSockets to 54.36.237.92. AGEWHEEZE supports extensive remote control and persistence mechanisms.
Despite the volume, infections were limited to a few personal devices in educational institutions, suggesting either poor attacker tradecraft or effective defenses. Detection should focus on network indicators like Files.fm download activity and WebSocket connections to the C2 server, as payload scanning may miss the password-protected archive contents. This campaign highlights the need to hunt beyond mailbox heuristics and endpoint scans in sectors including government, healthcare, finance, education, and software development.
1 source covering this story
CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
CERT-UA impersonation on March 26–27, 2026 spread AGEWHEEZE malware, infecting few devices despite 1M phishing emails.
Part of the PlainSec briefing for 2026-04-02