BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Ukraine Cyberattack Targets Government, Healthcare Data

Sophisticated malware campaign targets Ukrainian state bodies, stealing data and mining cryptocurrency.

  • Ukraine’s CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a cryptocurrency miner being installed on infected systems.
  • The attackers deployed a toolkit designed to steal sensitive data from Chromium browsers and WhatsApp, using tools like ChromElevator and ZAPiXDESK.
  • The final payloads included remote access tools like AGINGFLY and RAVENSHELL, as well as the XMRig cryptocurrency mining software.
  • The campaign leveraged compromised websites and AI-generated fake sites in phishing emails starting in March 2026.

A threat cluster tracked as UAC-0247 has been actively targeting Ukrainian government agencies and municipal healthcare clinics, leveraging sophisticated malware to steal data and mine cryptocurrency, according to a report from Ukraine’s Computer Emergencies Response Team (CERT-UA) detailing activity from March to April 2026. The attack chain begins with a phishing email disguised as a humanitarian aid proposal, which directs victims to a compromised or AI-generated fake website.

- Advertisement -

Consequently, the attack downloads a Windows Shortcut file that executes a remote HTML Application. This application displays a decoy form while secretly fetching a binary to inject malicious shellcode into a legitimate process like “runtimeBroker.exe.”

Meanwhile, the infection deploys multiple payloads for persistent access, including the RAVENSHELL reverse shell and the AGINGFLY remote access trojan. “At the same time, recent campaigns have recorded the use of a two-stage loader,” CERT-UA noted, describing its complex, encrypted structure.

The ultimate goal of the campaign is reconnaissance and data theft, facilitated by open-source tools. Attackers use tools like ZAPiXDESK to decrypt WhatsApp Web data and ChromElevator to bypass browser encryption for cookies and passwords.

Furthermore, the hackers utilize network scanners like RustScan and tunneling utilities such as Chisel for lateral movement. A final payload discovered in the attacks is XMRig, software designed to mine cryptocurrency on compromised machines.

- Advertisement -

However, the threat is not confined to government offices, as evidence suggests Ukrainian defense personnel were also targeted via malicious Signal messages. To defend against these attacks, CERT-UA recommends restricting the execution of scripts and specific legitimate system utilities often abused by the malware.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Errol Musk Reveals Elon, Kimbal Own $1.6B in Bitcoin

Errol Musk revealed that his sons, Elon and Kimbal, hold approximately $1.6 billion in...

Ether ETF Inflows Hit $248M Despite Bearish Futures

Institutional accumulation via ETH ETFs and Bitmine Immersion is supporting a spot-driven price recovery...

Hackers Weaponize AI Platform n8n for Phishing Campaigns

Threat actors are weaponizing the popular AI workflow automation platform n8n to conduct phishing...

Fake Ledger App on Apple Store Steals $9.5M in Crypto

Apple removed a fraudulent Ledger wallet app after an investigation revealed it was used...

Alibaba’s Qwen Code Ends Free Tier, Points to Paid Options

Alibaba has discontinued the free tier for its Qwen Code AI coding assistant, directing...

Must Read

5 Best Hacking eBooks for Beginners

In this article we present the 5 Best Hacking eBooks for beginners as ranked by our editorial teamWelcome to the world of hacking, where...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading