The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed information about a recent phishing effort in which a remote administration tool called AGEWHEEZE was distributed by impersonating the cybersecurity agency.
In order to disseminate a password-protected ZIP archive housed on Files.fm and encourage recipients to install the specialized software, the threat actors, identified as UAC-0255, wrote emails on March 26 and 27, 2026, pretending to be CERT-UA.
State agencies, healthcare facilities, security firms, academic institutions, financial institutions, and software development firms were among the campaign’s objectives. The email address incidents@cert-ua[.]tech was used to send some of the correspondence.
The agency’s “CERT_UA_protection_tool.zip” ZIP file is intended to download malware disguised as security software. According to CERT-UA, the malware is a remote access trojan with the code AGEWHEEZE read more about CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
