Threat reportMalwareTL-2026-0372

AgingFly Malware — UAC-0247 Targets Ukrainian Government Agencies and Hospitals with Novel Dynamic C2 RAT

highACTIVE

AgingFly Malware (TL-2026-0372), also tracked as AgingFly Campaign, is a high-severity malware campaign, first published 2026-04-15. It is attributed to UAC-0247 (Russia) with medium confidence, affects Ukrainian Government Local Government IT Systems, maps to 27 MITRE ATT&CK techniques (T1005, T1021, T1027), and is covered by 9 detection rules and 23 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
27MITRE ATT&CK
Actors
1UAC-0247
Detection rules
9SPL · KQL · Sigma
IOCs
23Indicators of compromise

Key facts for TL-2026-0372

Threat ID
TL-2026-0372
Also known as
AgingFly Campaign, UAC-0247 Campaign
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
Last reviewed
Attribution
UAC-0247
Attribution confidence
MEDIUM
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
government, healthcare, military, defense, public-sector
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
23

Malware and tooling in AgingFly Malware

Malware and tooling: AgingFly, RAVENSHELL, SILENTLOOP, AgingFly WebSocket RAT, Chisel, ChromElevator, Ligolo-ng, RAVENSHELL TCP C2, RustScan, ZAPiDESK

How AgingFly Malware works

CERT-UA tracks threat actor UAC-0247 deploying the novel AgingFly C# remote access trojan against Ukrainian local government agencies, hospitals, and Defense Forces representatives. The malware features dynamic runtime compilation of C2-supplied command handlers over AES-CBC encrypted WebSockets, with the infection chain leveraging humanitarian aid-themed phishing emails, LNK/HTA delivery chains, and a multi-stage loader culminating in browser credential theft, WhatsApp database decryption, keylogging, and lateral movement via open-source tunneling tools.

In April 2026, CERT-UA published advisory #6288271 detailing a sustained cyber-espionage campaign by threat actor UAC-0247 targeting Ukrainian local government agencies, hospitals, and Defense Forces representatives. The campaign, active since at least March 2026 with over a dozen investigated incidents, employs a novel malware family designated AgingFly — a C# remote access trojan with a distinctive architecture that retrieves command handlers as source code from the C2 server and compiles them dynamically at runtime.

The infection chain begins with spearphishing emails crafted around humanitarian aid themes. Embedded links direct victims to either compromised legitimate websites (exploited via cross-site scripting vulnerabilities) or AI-generated fake humanitarian aid sites. The landing page serves an archive containing a malicious LNK shortcut file. When executed, the LNK triggers an HTA (HTML Application) handler that retrieves and executes an HTA file from a remote resource. The HTA displays a decoy humanitarian aid form to the victim while silently creating a scheduled task for persistence.

The loader chain proceeds through multiple stages: a first-stage executable downloads and injects shellcode into a legitimate system process via process hollowing. The second stage employs a custom executable format with a compressed and encrypted final payload. A TCP reverse shell component designated RAVENSHELL — using XOR cipher encryption — establishes initial communication with a management server. The SILENTLOOP component, implemented as a PowerShell script, provides additional command execution capability and retrieves C2 configuration data via Telegram channels or fallback mechanisms.

AgingFly itself represents a significant evolution in RAT architecture. Unlike conventional trojans that ship with a fixed set of command handlers, AgingFly contains no built-in command handling logic. Instead, it establishes a WebSocket connection to its C2 server encrypted with AES-CBC using static keys, then receives C# source code for command handlers on demand. These handlers are compiled at runtime using the .NET CodeDomProvider/CSharpCodeProvider API, loaded into the running process, and executed. This design gives operators maximum flexibility to deploy new capabilities without updating the implant binary, while also complicating static analysis since the malware binary alone reveals no specific capabilities.

Post-exploitation activity observed in UAC-0247 operations leverages a toolkit of open-source offensive tools. ChromElevator is deployed for browser credential theft — it uses syscall-based process hollowing to inject into Chromium-based browser processes (Chrome, Edge, Brave), bypassing Application-Bound Encryption protections to extract saved passwords, cookies, and encryption keys from the Login Data and Cookies SQLite databases. ZAPiDESK, an open-source forensic utility, is repurposed for decrypting WhatsApp Windows desktop databases, enabling access to victims messaging data. Network reconnaissance is conducted with RustScan, a fast Rust-based port scanner, while lateral movement through compromised networks is facilitated by Ligolo-ng and Chisel tunneling proxies that establish reverse tunnels through network boundaries.

The targeting of Ukrainian healthcare infrastructure alongside government and military entities reflects an escalation in the Russia-Ukraine cyber conflict, with civilian critical infrastructure directly in scope. The dynamic compilation technique employed by AgingFly represents an evolution that challenges traditional signature-based detection, requiring defenders to focus on behavioral indicators such as runtime compilation events, WebSocket C2 patterns, and the characteristic tool deployment chain.

MITRE ATT&CK techniques used in TL-2026-0372

Collection

T1005 Data from Local System; T1113 Screen Capture

Lateral Movement

T1021 Remote Services

Defense Evasion

T1027 Obfuscated Files or Information; T1140 Deobfuscate/Decode Files or Information; T1218 System Binary Proxy Execution

Exfiltration

T1041 Exfiltration Over C2 Channel

Discovery

T1046 Network Service Discovery; T1082 System Information Discovery

Persistence

T1053 Scheduled Task/Job

Privilege Escalation

T1055 Process Injection

Credential Access

T1056 Input Capture; T1539 Steal Web Session Cookie; T1555 Credentials from Password Stores

Execution

T1059 Command and Scripting Interpreter; T1106 Native API; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1102 Web Service; T1572 Protocol Tunneling; T1573 Encrypted Channel

Impact

T1565 Data Manipulation

Initial Access

T1566 Phishing

Resource Development

T1584 Compromise Infrastructure; T1587 Develop Capabilities; T1608 Stage Capabilities

Reconnaissance

T1598 Phishing for Information

Affected products and versions in AgingFly Malware

  • Ukrainian Government — Local Government IT Systems
    Vulnerable versions: All
  • Ukrainian Healthcare — Hospital IT Infrastructure
    Vulnerable versions: All
  • Ukrainian Defense Forces — Military Personnel Endpoints
    Vulnerable versions: All
  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Google — Chrome
    Vulnerable versions: All Chromium-based browsers targeted by ChromElevator

Remediation for AgingFly Malware

Immediate actions

  • Block execution of LNK, HTA, and JS files from email attachments and downloads at the email gateway and endpoint
  • Deploy detection rules for mshta.exe spawning network connections or child processes
  • Monitor for csc.exe (C# compiler) invocations from non-development processes indicating runtime compilation
  • Block WebSocket connections to unknown external endpoints at the network perimeter
  • Hunt for scheduled tasks created by mshta.exe or HTA handlers across the environment
  • Block known Ligolo-ng, Chisel, and RustScan binaries via application control policies

Workarounds

  • Disable Windows Script Host and HTA execution via Group Policy where not required
  • Restrict PowerShell execution policy to AllSigned on sensitive systems
  • Block outbound Telegram API traffic (api.telegram.org) from endpoint subnets
  • Disable scheduled task creation for standard user accounts where feasible

Longer-term hardening

  • Deploy EDR with behavioral detection capabilities for process hollowing and runtime code compilation
  • Implement application whitelisting to prevent execution of unauthorized binaries including open-source offensive tools
  • Enable PowerShell Constrained Language Mode and Script Block Logging to detect SILENTLOOP activity
  • Segment hospital and government networks to limit lateral movement via tunneling tools
  • Implement phishing-resistant MFA for all privileged accounts
  • Deploy network monitoring for encrypted WebSocket tunnels and Telegram API communications from endpoints
  • Conduct user awareness training focused on humanitarian aid-themed social engineering lures

Timeline of AgingFly Malware

  • Earliest observed UAC-0247 activity targeting Ukrainian local government agencies and hospitals with AgingFly malware, based on CERT-UA incident investigations
  • Campaign expands to target Ukrainian Defense Forces representatives alongside government and healthcare targets; over a dozen incidents under investigation by CERT-UA
  • Post-exploitation tools including ChromElevator, ZAPiDESK, RustScan, Ligolo-ng, and Chisel observed in UAC-0247 operations for credential theft, reconnaissance, and lateral movement
  • CERT-UA completes technical analysis of AgingFly malware revealing dynamic runtime compilation architecture, AES-CBC encrypted WebSocket C2, and multi-stage loader chain
  • BleepingComputer publishes article detailing AgingFly capabilities, infection chain, and post-exploitation tooling used by UAC-0247 against Ukrainian targets
  • CERT-UA publishes advisory #6288271 with full technical details on UAC-0247 campaign and AgingFly malware family; BleepingComputer provides public reporting
  • As of 2026-05-29, UAC-0247's AgingFly C# RAT campaign against Ukrainian government, hospitals, and defense/FPV-drone operators remains a live espionage threat with no takedown, arrests, or sinkhole reported. CERT-UA (April advisory) and multiple outlets describe an expanding, undisrupted Russia-suspected operation; no CVEs to patch and dynamic runtime-compiled C2 keeps it evasive.

Sources cited for AgingFly Malware

Detection coverage for TL-2026-0372

As of 2026-04-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0372 across Splunk SPL, Microsoft KQL and Sigma, covering 23 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
23 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats