BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Ukraine Cyberattack Targets Government, Healthcare Data

Sophisticated malware campaign targets Ukrainian state bodies, stealing data and mining cryptocurrency.

  • Ukraine’s CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a cryptocurrency miner being installed on infected systems.
  • The attackers deployed a toolkit designed to steal sensitive data from Chromium browsers and WhatsApp, using tools like ChromElevator and ZAPiXDESK.
  • The final payloads included remote access tools like AGINGFLY and RAVENSHELL, as well as the XMRig cryptocurrency mining software.
  • The campaign leveraged compromised websites and AI-generated fake sites in phishing emails starting in March 2026.

A threat cluster tracked as UAC-0247 has been actively targeting Ukrainian government agencies and municipal healthcare clinics, leveraging sophisticated malware to steal data and mine cryptocurrency, according to a report from Ukraine’s Computer Emergencies Response Team (CERT-UA) detailing activity from March to April 2026. The attack chain begins with a phishing email disguised as a humanitarian aid proposal, which directs victims to a compromised or AI-generated fake website.

- Advertisement -

Consequently, the attack downloads a Windows Shortcut file that executes a remote HTML Application. This application displays a decoy form while secretly fetching a binary to inject malicious shellcode into a legitimate process like “runtimeBroker.exe.”

Meanwhile, the infection deploys multiple payloads for persistent access, including the RAVENSHELL reverse shell and the AGINGFLY remote access trojan. “At the same time, recent campaigns have recorded the use of a two-stage loader,” CERT-UA noted, describing its complex, encrypted structure.

The ultimate goal of the campaign is reconnaissance and data theft, facilitated by open-source tools. Attackers use tools like ZAPiXDESK to decrypt WhatsApp Web data and ChromElevator to bypass browser encryption for cookies and passwords.

Furthermore, the hackers utilize network scanners like RustScan and tunneling utilities such as Chisel for lateral movement. A final payload discovered in the attacks is XMRig, software designed to mine cryptocurrency on compromised machines.

- Advertisement -

However, the threat is not confined to government offices, as evidence suggests Ukrainian defense personnel were also targeted via malicious Signal messages. To defend against these attacks, CERT-UA recommends restricting the execution of scripts and specific legitimate system utilities often abused by the malware.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Drake’s New Song Demands Pardon for SBF

Drake called for the release of imprisoned FTX founder Sam Bankman-Fried in a lyric...

NIO’s Onvo L80 SUV Launches, Deliveries Start Saturday

Nio's mass-market subsidiary, Onvo, officially launched the L80 family SUV on Friday, with deliveries...

Liberland Honors Ethereum Founder Buterin With Star-Shaped Medal

Vitalik Buterin received the "First Class Order of Merit of the Star of Liberland"...

Firm seeks $344M in frozen Tether tied to Iran

Gerstein Harrow LLP is seeking a court order to compel Tether to release over...

Turla’s Kazuar Malware Evolves Into Stealthy P2P Botnet

The Russian state-sponsored group Turla (aka Secret Blizzard) has evolved its Kazuar malware into...

Must Read

Top 5 Testing Tools For Blockchain Applications in 2022

Blockchain apps have been adopted popularly by some prominent industries due to its being a decentralized-designed technology. Furthermore, these apps eliminate the risks that...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading