惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

GbyAI
GbyAI
Martin Fowler
Martin Fowler
云风的 BLOG
云风的 BLOG
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
T
The Blog of Author Tim Ferriss
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
小众软件
小众软件
博客园_首页
博客园 - 聂微东
罗磊的独立博客
Recent Announcements
Recent Announcements
U
Unit 42
N
Netflix TechBlog - Medium
Blog — PlanetScale
Blog — PlanetScale
阮一峰的网络日志
阮一峰的网络日志
博客园 - 叶小钗
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog
博客园 - Franky
D
DataBreaches.Net
Last Week in AI
Last Week in AI

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
AgingFly malware targets Ukraine government, hospitals
Vlad CONSTANTINESCU · 2026-04-16 · via Consumer Insights

CERT-UA links a new credential-stealing campaign to phishing, browser theft and modular remote access.

Phishing lure initial vector

Ukraine’s national cyber response team (CERT-UA) has uncovered a new malware family, dubbed AgingFly, in attacks on local government bodies and hospitals. Forensic evidence suggests some Defense Forces representatives may also have been targeted. CERT-UA tracks the activity under the UAC-0247 cluster.

According to the incident report, the campaign begins with emails disguised as offers of humanitarian aid. Recipients are then pushed toward a malicious archive delivered through either a compromised legitimate site abused via XSS or an AI-generated fake page designed to look credible.

Shortcuts, scripts and a staged payload

Once opened, the archive drops an LNK shortcut that abuses Windows’ HTA handler to fetch additional code remotely. A decoy form appears on screen while the infection chain establishes persistence through a scheduled task and launches an EXE payload that injects shellcode into a legitimate process.

CERT-UA says the operation then moves through a multi-stage loader, using encrypted communications and remote command execution. A PowerShell component known as SILENTLOOP helps run commands, update configuration data and pull command-and-control details from a Telegram channel or fallback mechanisms.

Browser and WhatsApp data in focus

The attackers appear especially interested in harvesting user data. Investigators say the cluster used ChromElevator to decrypt and extract cookies and saved passwords from Chromium-based browsers, while ZAPiDESK was leveraged to access sensitive information stored by WhatsApp for Windows.

The investigations also found signs of reconnaissance and lateral movement, including the use of RustScan, Ligolo-ng and Chisel. That combination suggests the operators are not just stealing credentials but also preparing for deeper access across compromised environments.

What makes AgingFly stand out

CERT-UA says AgingFly is a C# backdoor capable of command execution, file theft, screenshots, keylogging and arbitrary code execution. What makes it unusual is that it does not carry all of its command handlers inside the initial implant. Instead, it retrieves source code from its server and compiles those capabilities directly on the infected machine.

That design keeps the initial payload lean and flexible, while increasing operational complexity. CERT-UA’s immediate advice is to restrict the launch of LNK, HTA and JS files to disrupt the infection chain before AgingFly can fully deploy.

The importance of dedicated security software

Bitdefender Ultimate Security can help reduce the risk from threats like AgingFly by combining malware detection with anti-phishing and scam protection, potentially stopping users before they interact with the malicious links or files that launch the attack.

In campaigns centered on stolen credentials and compromised sessions, that layered approach is crucial because it can help block payloads, flag deceptive content and limit exposure if attackers go after browser-stored data.