Threat reportMalwareTL-2026-0372
AgingFly Malware — UAC-0247 Targets Ukrainian Government Agencies and Hospitals with Novel Dynamic C2 RAT
AgingFly Malware (TL-2026-0372), also tracked as AgingFly Campaign, is a high-severity malware campaign, first published 2026-04-15. It is attributed to UAC-0247 (Russia) with medium confidence, affects Ukrainian Government Local Government IT Systems, maps to 27 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 23 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 27MITRE ATT&CK
- Actors
- 1UAC-0247
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 23Indicators of compromise
Key facts for TL-2026-0372
- Threat ID
- TL-2026-0372
- Also known as
- AgingFly Campaign, UAC-0247 Campaign
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UAC-0247
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, healthcare, military, defense, public-sector
- Target regions
- Ukraine, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 23
Malware and tooling in AgingFly Malware
Malware and tooling: AgingFly, RAVENSHELL, SILENTLOOP, AgingFly WebSocket RAT, Chisel, ChromElevator, Ligolo-ng, RAVENSHELL TCP C2, RustScan, ZAPiDESK
How AgingFly Malware works
CERT-UA tracks threat actor UAC-0247 deploying the novel AgingFly C# remote access trojan against Ukrainian local government agencies, hospitals, and Defense Forces representatives. The malware features dynamic runtime compilation of C2-supplied command handlers over AES-CBC encrypted WebSockets, with the infection chain leveraging humanitarian aid-themed phishing emails, LNK/HTA delivery chains, and a multi-stage loader culminating in browser credential theft, WhatsApp database decryption, keylogging, and lateral movement via open-source tunneling tools.
In April 2026, CERT-UA published advisory #6288271 detailing a sustained cyber-espionage campaign by threat actor UAC-0247 targeting Ukrainian local government agencies, hospitals, and Defense Forces representatives. The campaign, active since at least March 2026 with over a dozen investigated incidents, employs a novel malware family designated AgingFly — a C# remote access trojan with a distinctive architecture that retrieves command handlers as source code from the C2 server and compiles them dynamically at runtime.
The infection chain begins with spearphishing emails crafted around humanitarian aid themes. Embedded links direct victims to either compromised legitimate websites (exploited via cross-site scripting vulnerabilities) or AI-generated fake humanitarian aid sites. The landing page serves an archive containing a malicious LNK shortcut file. When executed, the LNK triggers an HTA (HTML Application) handler that retrieves and executes an HTA file from a remote resource. The HTA displays a decoy humanitarian aid form to the victim while silently creating a scheduled task for persistence.
The loader chain proceeds through multiple stages: a first-stage executable downloads and injects shellcode into a legitimate system process via process hollowing. The second stage employs a custom executable format with a compressed and encrypted final payload. A TCP reverse shell component designated RAVENSHELL — using XOR cipher encryption — establishes initial communication with a management server. The SILENTLOOP component, implemented as a PowerShell script, provides additional command execution capability and retrieves C2 configuration data via Telegram channels or fallback mechanisms.
AgingFly itself represents a significant evolution in RAT architecture. Unlike conventional trojans that ship with a fixed set of command handlers, AgingFly contains no built-in command handling logic. Instead, it establishes a WebSocket connection to its C2 server encrypted with AES-CBC using static keys, then receives C# source code for command handlers on demand. These handlers are compiled at runtime using the .NET CodeDomProvider/CSharpCodeProvider API, loaded into the running process, and executed. This design gives operators maximum flexibility to deploy new capabilities without updating the implant binary, while also complicating static analysis since the malware binary alone reveals no specific capabilities.
Post-exploitation activity observed in UAC-0247 operations leverages a toolkit of open-source offensive tools. ChromElevator is deployed for browser credential theft — it uses syscall-based process hollowing to inject into Chromium-based browser processes (Chrome, Edge, Brave), bypassing Application-Bound Encryption protections to extract saved passwords, cookies, and encryption keys from the Login Data and Cookies SQLite databases. ZAPiDESK, an open-source forensic utility, is repurposed for decrypting WhatsApp Windows desktop databases, enabling access to victims messaging data. Network reconnaissance is conducted with RustScan, a fast Rust-based port scanner, while lateral movement through compromised networks is facilitated by Ligolo-ng and Chisel tunneling proxies that establish reverse tunnels through network boundaries.
The targeting of Ukrainian healthcare infrastructure alongside government and military entities reflects an escalation in the Russia-Ukraine cyber conflict, with civilian critical infrastructure directly in scope. The dynamic compilation technique employed by AgingFly represents an evolution that challenges traditional signature-based detection, requiring defenders to focus on behavioral indicators such as runtime compilation events, WebSocket C2 patterns, and the characteristic tool deployment chain.
MITRE ATT&CK techniques used in TL-2026-0372
Collection
T1005 Data from Local System; T1113 Screen Capture
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution
Exfiltration
T1041 Exfiltration Over C2 Channel
Discovery
T1046 Network Service Discovery; T1082 System Information Discovery
Persistence
Privilege Escalation
Credential Access
T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1102 Web Service; T1572 Protocol Tunneling; T1573 Encrypted Channel
Impact
Initial Access
Resource Development
T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities
Reconnaissance
Affected products and versions in AgingFly Malware
- Ukrainian Government — Local Government IT Systems
Vulnerable versions: All - Ukrainian Healthcare — Hospital IT Infrastructure
Vulnerable versions: All - Ukrainian Defense Forces — Military Personnel Endpoints
Vulnerable versions: All - Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Google — Chrome
Vulnerable versions: All Chromium-based browsers targeted by ChromElevator
Remediation for AgingFly Malware
Immediate actions
- Block execution of LNK, HTA, and JS files from email attachments and downloads at the email gateway and endpoint
- Deploy detection rules for mshta.exe spawning network connections or child processes
- Monitor for csc.exe (C# compiler) invocations from non-development processes indicating runtime compilation
- Block WebSocket connections to unknown external endpoints at the network perimeter
- Hunt for scheduled tasks created by mshta.exe or HTA handlers across the environment
- Block known Ligolo-ng, Chisel, and RustScan binaries via application control policies
Workarounds
- Disable Windows Script Host and HTA execution via Group Policy where not required
- Restrict PowerShell execution policy to AllSigned on sensitive systems
- Block outbound Telegram API traffic (api.telegram.org) from endpoint subnets
- Disable scheduled task creation for standard user accounts where feasible
Longer-term hardening
- Deploy EDR with behavioral detection capabilities for process hollowing and runtime code compilation
- Implement application whitelisting to prevent execution of unauthorized binaries including open-source offensive tools
- Enable PowerShell Constrained Language Mode and Script Block Logging to detect SILENTLOOP activity
- Segment hospital and government networks to limit lateral movement via tunneling tools
- Implement phishing-resistant MFA for all privileged accounts
- Deploy network monitoring for encrypted WebSocket tunnels and Telegram API communications from endpoints
- Conduct user awareness training focused on humanitarian aid-themed social engineering lures
Timeline of AgingFly Malware
- Earliest observed UAC-0247 activity targeting Ukrainian local government agencies and hospitals with AgingFly malware, based on CERT-UA incident investigations
- Campaign expands to target Ukrainian Defense Forces representatives alongside government and healthcare targets; over a dozen incidents under investigation by CERT-UA
- Post-exploitation tools including ChromElevator, ZAPiDESK, RustScan, Ligolo-ng, and Chisel observed in UAC-0247 operations for credential theft, reconnaissance, and lateral movement
- CERT-UA completes technical analysis of AgingFly malware revealing dynamic runtime compilation architecture, AES-CBC encrypted WebSocket C2, and multi-stage loader chain
- BleepingComputer publishes article detailing AgingFly capabilities, infection chain, and post-exploitation tooling used by UAC-0247 against Ukrainian targets
- CERT-UA publishes advisory #6288271 with full technical details on UAC-0247 campaign and AgingFly malware family; BleepingComputer provides public reporting
- As of 2026-05-29, UAC-0247's AgingFly C# RAT campaign against Ukrainian government, hospitals, and defense/FPV-drone operators remains a live espionage threat with no takedown, arrests, or sinkhole reported. CERT-UA (April advisory) and multiple outlets describe an expanding, undisrupted Russia-suspected operation; no CVEs to patch and dynamic runtime-compiled C2 keeps it evasive.
Sources cited for AgingFly Malware
- BleepingComputer — New AgingFly malware used in attacks on Ukraine govt, hospitals
- CERT-UA Advisory #6288271 — UAC-0247 Campaign Analysis
- ChromElevator — Syscall-Based Process Hollowing Against Chromium ABE
- Ligolo-ng — Advanced Tunneling/Pivoting Tool (GitHub)
- CERT-UA — Computer Emergency Response Team of Ukraine
- MITRE ATT&CK — Process Injection: Process Hollowing T1055.012
- MITRE ATT&CK — System Binary Proxy Execution: Mshta T1218.005
Detection coverage for TL-2026-0372
As of 2026-04-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0372 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.