BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Ukraine Cyberattack Targets Government, Healthcare Data

Sophisticated malware campaign targets Ukrainian state bodies, stealing data and mining cryptocurrency.

  • Ukraine’s CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a cryptocurrency miner being installed on infected systems.
  • The attackers deployed a toolkit designed to steal sensitive data from Chromium browsers and WhatsApp, using tools like ChromElevator and ZAPiXDESK.
  • The final payloads included remote access tools like AGINGFLY and RAVENSHELL, as well as the XMRig cryptocurrency mining software.
  • The campaign leveraged compromised websites and AI-generated fake sites in phishing emails starting in March 2026.

A threat cluster tracked as UAC-0247 has been actively targeting Ukrainian government agencies and municipal healthcare clinics, leveraging sophisticated malware to steal data and mine cryptocurrency, according to a report from Ukraine’s Computer Emergencies Response Team (CERT-UA) detailing activity from March to April 2026. The attack chain begins with a phishing email disguised as a humanitarian aid proposal, which directs victims to a compromised or AI-generated fake website.

- Advertisement -

Consequently, the attack downloads a Windows Shortcut file that executes a remote HTML Application. This application displays a decoy form while secretly fetching a binary to inject malicious shellcode into a legitimate process like “runtimeBroker.exe.”

Meanwhile, the infection deploys multiple payloads for persistent access, including the RAVENSHELL reverse shell and the AGINGFLY remote access trojan. “At the same time, recent campaigns have recorded the use of a two-stage loader,” CERT-UA noted, describing its complex, encrypted structure.

The ultimate goal of the campaign is reconnaissance and data theft, facilitated by open-source tools. Attackers use tools like ZAPiXDESK to decrypt WhatsApp Web data and ChromElevator to bypass browser encryption for cookies and passwords.

Furthermore, the hackers utilize network scanners like RustScan and tunneling utilities such as Chisel for lateral movement. A final payload discovered in the attacks is XMRig, software designed to mine cryptocurrency on compromised machines.

- Advertisement -

However, the threat is not confined to government offices, as evidence suggests Ukrainian defense personnel were also targeted via malicious Signal messages. To defend against these attacks, CERT-UA recommends restricting the execution of scripts and specific legitimate system utilities often abused by the malware.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

“GothFerrari” Gets Over 6 Years for $250M Crypto Heist

Marlon "GothFerrari" Ferro was sentenced to 78 months in prison for his role in...

NEAR Devs: Blockchains Must Plan for Post-Quantum Fraud

Quantum computers could potentially crack blockchain cryptography, threatening wallet security.Near Protocol researchers argue protocols...

Critical Flaws Found in vm2 Node.js Sandbox Library

vm2 Node.js library users must urgently update to version 3.11.2 to patch twelve critical...

US Bitcoin Reserve & Crypto Law Clarity Weeks Away

White House advisor Patrick Witt says the CLARITY Act could pass by July 4,...

Musk Claims He’ll End Up Paying Trillions In Taxes

Elon Musk claims a combined 45% federal and state tax rate applies when he...

Must Read

Ethereum Hosting: TOP 10 Companies to Buy Hosting With Ethereum

If you are looking for Ethereum Hosting, you've hit the jackpot. In this article, we will present the 10 Best companies to buy hosting...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading