UAC-0255 Distributes AGEWHEEZE RAT via CERT-UA Impersonation Campaign Targeting Ukrainian Critical Sectors — Threadlinqs Intelligence
As of 2026-05-30, UAC-0255 Distributes AGEWHEEZE RAT via CERT-UA Impersonation Campaign Targeting Ukrainian Critical Sectors is a high-severity apt threat attributed to Cyber Serp (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 15 indicators of compromise.
Threat ID: TL-2026-0308 · Severity: HIGH · Status: MONITORING · Category: APT
Attribution: Cyber Serp · Russia · HACKTIVISM
Pro-Russian threat actor UAC-0255 impersonated Ukraine's CERT-UA to distribute the Go-based AGEWHEEZE remote access trojan via phishing emails and password-protected archives hosted on Files.fm,
In late March 2026, threat actor UAC-0255 launched a phishing campaign impersonating Ukraine's Computer Emergency Response Team (CERT-UA) to distribute AGEWHEEZE, a full-featured remote access trojan written in the Go programming language. The campaign targeted a broad cross-section of Ukrainian organizations including government agencies, medical centers, cybersecurity firms, educational institutions, financial organizations, and software development companies.
The attack chain began with phishing emails warning recipients of a supposed large-scale cyberattack from Russia, directing them to download password-protected ZIP archives (CERT_UA_protection_tool.zip, protection_tool.zip) from the Files.fm file-sharing service. The attackers registered a fraudulent domain, cert-ua[.]tech, on March 27 — one day into the distribution window — which replicated content from the legitimate cert.gov.ua website and included fabricated instructions for downloading the malicious payload disguised as official security software.
AGEWHEEZE provides comprehensive remote access capabilities including command execution, file system operations (read, write, delete, rename, directory creation), screen content streaming and capture, mouse and keyboard input emulation, clipboard read/write access, process and service management, autorun management, terminal access, and the ability to open arbitrary URLs on compromised hosts.
The malware establishes persistence through three mechanisms: Windows registry startup keys, Startup folder placement, and scheduled task creation. Depending on the infection path, persistence entries are named either SvcHelper or CoreService. The internal Go package path /example.com/tvisor/agent was identified within the malware binary.
Command-and-control communications are conducted over WebSocket connections to infrastructure hosted on OVH (AS16276) using port 8443/tcp. The C2 server presented a web page titled The Cult with an authentication form and contained Russian-language strings in its HTML source. A self-signed SSL certificate on the server was created on March 18, 2026, with TVisor listed in the Organization field — matching the internal package name found in the malware.
Attribution points to the CyberSerp hacker group, which claimed responsibility via its Telegram channel on March 28, 2026. The fake CERT-UA website contained the embedded message With Love, CYBER SERP alongside a link to the CyberSerp_Official Telegram channel. The group claimed to have sent approximately one million malicious emails to Ukr.net users and compromised over 200,000 devices, though CERT-UA assessed the campaign as largely unsuccessful with minimal confirmed infections.
CERT-UA published advisory #21075 documenting the campaign and recommended AppLocker/Software Restriction Policies and endpoint protection measures as countermeasures.
Target sectors: government, healthcare, education, financial-services, cybersecurity, software-development
Target regions: Ukraine, Eastern Europe
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 15 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
APT, HIGH, threat intelligence, cybersecurity, T1583, T1583, T1608, T1566, T1566, T1053, T1204, T1547, T1053, T1027