BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Ukraine Cyberattack Targets Government, Healthcare Data

Sophisticated malware campaign targets Ukrainian state bodies, stealing data and mining cryptocurrency.

  • Ukraine’s CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a cryptocurrency miner being installed on infected systems.
  • The attackers deployed a toolkit designed to steal sensitive data from Chromium browsers and WhatsApp, using tools like ChromElevator and ZAPiXDESK.
  • The final payloads included remote access tools like AGINGFLY and RAVENSHELL, as well as the XMRig cryptocurrency mining software.
  • The campaign leveraged compromised websites and AI-generated fake sites in phishing emails starting in March 2026.

A threat cluster tracked as UAC-0247 has been actively targeting Ukrainian government agencies and municipal healthcare clinics, leveraging sophisticated malware to steal data and mine cryptocurrency, according to a report from Ukraine’s Computer Emergencies Response Team (CERT-UA) detailing activity from March to April 2026. The attack chain begins with a phishing email disguised as a humanitarian aid proposal, which directs victims to a compromised or AI-generated fake website.

- Advertisement -

Consequently, the attack downloads a Windows Shortcut file that executes a remote HTML Application. This application displays a decoy form while secretly fetching a binary to inject malicious shellcode into a legitimate process like “runtimeBroker.exe.”

Meanwhile, the infection deploys multiple payloads for persistent access, including the RAVENSHELL reverse shell and the AGINGFLY remote access trojan. “At the same time, recent campaigns have recorded the use of a two-stage loader,” CERT-UA noted, describing its complex, encrypted structure.

The ultimate goal of the campaign is reconnaissance and data theft, facilitated by open-source tools. Attackers use tools like ZAPiXDESK to decrypt WhatsApp Web data and ChromElevator to bypass browser encryption for cookies and passwords.

Furthermore, the hackers utilize network scanners like RustScan and tunneling utilities such as Chisel for lateral movement. A final payload discovered in the attacks is XMRig, software designed to mine cryptocurrency on compromised machines.

- Advertisement -

However, the threat is not confined to government offices, as evidence suggests Ukrainian defense personnel were also targeted via malicious Signal messages. To defend against these attacks, CERT-UA recommends restricting the execution of scripts and specific legitimate system utilities often abused by the malware.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

3 Cryptocurrencies Near All-Time Highs As Market Recovers

Bitcoin recovered to $67,000 on June 15, 2026, following a dip below $60,000.Hyperliquid (HYPE)...

Hype ETFs Near $172M Inflows Defying Bitcoin ETF Exodus

Cumulative inflows for three new Hyperliquid ETFs reached nearly $172 million in roughly a...

Robinhood Lays Off 10% Staff Amid Record Trading

Robinhood Markets is cutting 10% of its full-time staff in a "proactive operational move"...

Saylor: Bitcoin doesn’t need staking or protocol yield

MicroStrategy executive chairman Michael Saylor argues Bitcoin does not need staking or yield mechanisms...

North Korean Hackers Impersonate Microsoft Alerts

North Korean hacking group ScarCruft (APT37) is using spear-phishing emails disguised as Microsoft security...

Must Read

Top 7 BEST Crypto Trading Bots for Beginners

QUICK NAVIGATIONQuick Look: Top 3 Best Crypto Trading BotsWhat Exactly is a Crypto Trading Bot?How I Chose These Trading BotsTop 7 Crypto Trading Bots...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading