Tag: CERT-UA

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails
News

CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed information about a recent phishing effort in which a remote administration tool called AGEWHEEZE was distributed by impersonating the cybersecurity agency. In order to disseminate a password-protected ZIP archive housed on Files.fm and encourage recipients to install the specialized software, the threat actors, identified as UAC-0255, wrote emails on March 26 and 27, 2026, pretending to be CERT-UA. State agencies, healthcare facilities, security firms, academic institutions, financial institutions, and software development firms were among the campaign's objectives. The email address incidents@cert-ua[.]tech was used to send some of the correspondence. The agency's "CERT_UA_protection_tool.zip" ZIP file is in...
CERT-UA Reports Cyberattacks Targeting Ukrainian State Systems with WRECKSTEEL Malware
News

CERT-UA Reports Cyberattacks Targeting Ukrainian State Systems with WRECKSTEEL Malware

According to the Computer Emergency Response Team of Ukraine (CERT-UA), at least three cyberattacks targeting the nation's vital infrastructure and state administration entities were documented with the intention of stealing private information. According to the CIA, the effort involved sending phishing messages with links to trustworthy sites like Google Drive and DropMeFiles using hacked email accounts. The links are occasionally included in PDF attachments. By stating that a Ukrainian government agency intended to reduce salary, the digital messages attempted to create a false feeling of urgency and urged the receiver to click on the link in order to check the list of impacted personnel. By clicking on these URLs, a Visual Basic Script (VBS) loader is downloaded, which is inte...
CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits
News

CERT-UA Warns of Cyber Scams Using Fake AnyDesk Requests for Fraudulent Security Audits

Unknown threat actors are attempting to pose as the cybersecurity agency by issuing AnyDesk connection requests, the Computer Emergency Response Team of Ukraine (CERT-UA) is alerting the public about. CERT-UA said that the AnyDesk requests purport to be for auditing the "level of security," warning enterprises to be alert for attempts at social engineering that aim to take advantage of user confidence. It's crucial to remember that CERT-UA may employ remote access software like AnyDesk in specific situations, the organization stated. Nevertheless, such measures are only implemented with prior consent with the owners of cyber defense objects via channels of communication that have been authorized by the government read more about CERT-UA Warns of Cyber Scams Using Fake AnyDesk Reques...