惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Azure Blog
Microsoft Azure Blog
aimingoo的专栏
aimingoo的专栏
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
MongoDB | Blog
MongoDB | Blog
月光博客
月光博客
The Cloudflare Blog
量子位
T
Tailwind CSS Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
B
Blog
MyScale Blog
MyScale Blog
T
The Blog of Author Tim Ferriss
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
D
DataBreaches.Net
V
Visual Studio Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Last Week in AI
Last Week in AI
U
Unit 42
博客园 - 聂微东
有赞技术团队
有赞技术团队
A
About on SuperTechFans

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
Fake CERT-UA emails spread AGEWHEEZE in ukraine
Vlad CONSTANTINESCU · 2026-04-02 · via Consumer Insights

A CERT-UA spoofing campaign used fake security tools to spread remote access malware to numerous email addresses.

CERT-UA used as a phishing lure

Ukraine’s cyber defenders are warning of a phishing operation that abused the CERT-UA brand to trick people into installing malware disguised as protection software. According to the agency, the activity was tied to UAC-0255 and relied on emails sent on March 26 and 27 to a broad mix of targets, including public sector bodies, healthcare providers, financial institutions, educators, security firms and software companies.

The malicious messages directed victims to a password-protected archive hosted on Files[.]fm and, in some cases, used the address incidents@cert-ua[.]tech to appear legitimate. The fake domain mimicked CERT-UA branding closely enough to reinforce the illusion that recipients were being offered an official defensive utility.

AGEWHEEZE was built for hands-on control

Inside the archive was AGEWHEEZE, a Go-based remote access trojan capable of turning an infected Windows machine into a remotely managed foothold. CERT-UA said the malware communicates with an external server over WebSockets and can execute commands, manipulate files, monitor the clipboard, emulate keyboard and mouse actions, capture screenshots and manage processes and services.

The malware also supports persistence through scheduled tasks, Registry changes or Startup folder placement, giving operators multiple ways to maintain access even after reboot. In practical terms, AGEWHEEZE functions less as a smash-and-grab implant and more as a flexible post-compromise tool suited to sustain surveillance or follow-on intrusion activity.

Big distribution, but with limited impact

While the actor-linked Telegram presence Cyber Serp claimed the campaign reached 1 million ukr.net mailboxes and compromised more than 200,000 devices, CERT-UA’s own assessment was far less dramatic. The agency said it identified only a small number of infected personal devices tied to employees at educational institutions and provided direct response support.

In scenarios like these, the importance of using dedicated security solutions cannot be overstated. Bitdefender Ultimate Security can help defend against phishing-led attacks like this through layered protections that include email scanning, scam detection, malicious download blocking, web protection and behavior-based threat monitoring designed to spot suspicious activity even when malware wears legitimate disguises.