UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian Hospitals, Local Government, and FPV Drone Operators
UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian (TL-2026-0377), also tracked as AGINGFLY Campaign, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-16. It is attributed to UAC-0247 (Russia) with high confidence, affects Microsoft Windows, maps to 27 MITRE ATT&CK techniques (T1003, T1027, T1036), and is covered by 9 detection rules and 24 indicators of compromise.
Key facts for TL-2026-0377
- Threat ID
- TL-2026-0377
- Also known as
- AGINGFLY Campaign, Operation AGINGFLY
- Severity
- HIGH
- CVSS
- 8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L)
- Status
- ACTIVE
- Category
- MALWARE
- First published
- 2026-04-16
- Last reviewed
- 2026-04-16
- Attribution
- UAC-0247
- Attribution confidence
- HIGH
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- healthcare, government, defense-industrial-base, critical-infrastructure, non-profit
- Target regions
- Ukraine, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
Malware and tooling: AGINGFLY, SPYCLOAK, Mimikatz, SharpHound
Russia-aligned threat actor UAC-0247 is conducting a targeted spearphishing campaign delivering a previously undocumented backdoor named AGINGFLY against Ukrainian critical infrastructure. CERT-UA confirms compromises across regional hospitals, municipal administrations, and civilian FPV (first-person-view) drone operator workshops, with objectives spanning espionage, credential theft, and network reconnaissance for follow-on operations. The malware's custom C2 protocol, LNK-based delivery chain, and use of legitimate Ukrainian-language lures (procurement invoices, medical supply notices, drone parts purchase orders) demonstrate the operator's deep familiarity with the target environment and its operational tempo.
How UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian works
On 15 April 2026, CERT-UA published an advisory attributing a cluster of intrusions against Ukrainian healthcare providers, oblast-level government bodies, and non-state FPV drone production workshops to UAC-0247, a Russia-aligned intrusion set first tracked by CERT-UA in late 2024 for operations against Ukrainian Defence Forces and military-adjacent suppliers. The current campaign introduces AGINGFLY, a bespoke .NET backdoor that had not been observed prior to February 2026 and which CERT-UA assesses with high confidence to be developed and operated exclusively by UAC-0247.
Initial access is obtained through spearphishing emails written in fluent Ukrainian, typically impersonating procurement officers, pharmacy distributors, or drone component suppliers. Messages deliver password-protected ZIP or RAR archives containing a decoy PDF and a Windows shortcut (.LNK) file. When the shortcut is executed, it invokes forfiles.exe or cmd.exe to launch a packaged HTA that stages AGINGFLY via a DLL sideloaded by a renamed, legitimate signed binary (AnyDesk.exe, vmnat.exe, or Adobe components). The loader decrypts AGINGFLY from an RC4-encrypted blob embedded in an accompanying .dat file and injects it into the host process.
AGINGFLY provides its operators with a capable but relatively compact feature set: arbitrary command execution, secure file upload and download, process listing and termination, screenshot capture, clipboard monitoring, and an in-memory credential harvester that scrapes browser login data, WiFi profiles, and Windows DPAPI master keys. Persistence is achieved either through a Scheduled Task named 'WindowsDefenderMaintenance' or through COM hijacking of the MruPidlList key under HKCU, depending on operator discretion. Command-and-control traffic is tunnelled over HTTPS to compromised Ukrainian small-business websites acting as redirectors, with final hop infrastructure hosted on bulletproof providers in Russia and Belarus. Beacon cadence is randomised between 45 and 180 seconds, with JSON payloads RC4-encrypted using a per-implant key negotiated via a custom handshake.
CERT-UA reports at least nine confirmed victims as of 14 April 2026: three oblast-level municipal administrations (including Poltava and Sumy), four regional hospitals involved in frontline trauma care, and two civilian FPV drone assembly workshops that have publicly crowdfunded for the Armed Forces of Ukraine. Post-exploitation activity observed to date includes staging of Mimikatz, enumeration of Active Directory via SharpHound, and exfiltration of patient record databases, municipal procurement documents, and drone hardware schematics. No destructive or ransomware activity has been observed, consistent with UAC-0247's espionage-focused mission.
Attribution to UAC-0247 (and by extension to a Russia-aligned intelligence-gathering effort) is based on overlapping code lineage between AGINGFLY and the earlier SPYCLOAK implant used in 2025 Defence Forces intrusions, reuse of specific registry persistence tradecraft, phishing infrastructure registered through the same set of bulletproof registrars, and CERT-UA's first-party victim telemetry. Defenders should prioritise email gateway inspection for password-protected archives containing LNKs, application allowlisting to break DLL sideloading chains, and EDR detections for the listed persistence mechanisms.
MITRE ATT&CK techniques used in TL-2026-0377
Credential Access
T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1574 Hijack Execution Flow
Exfiltration
T1041 Exfiltration Over C2 Channel
Persistence
T1053 Scheduled Task/Job; T1546 Event Triggered Execution
Execution
T1059 Command and Scripting Interpreter; T1204 User Execution
Command and Control
T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel
Discovery
T1082 System Information Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery
Collection
T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data
stealth
T1218 System Binary Proxy Execution
Initial Access
Resource Development
T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities
Reconnaissance
Affected products and versions in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2019; Server 2022 - Multi-vendor — Legitimate signed binaries abused for DLL sideloading (AnyDesk, VMware Workstation, Adobe Reader components)
Vulnerable versions: abused as loader host, not vulnerable products
Remediation for UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
Patches
- No CVE-based patch applies; this is a social-engineering-led malware campaign rather than a software vulnerability
Immediate actions
- Block AGINGFLY C2 domains and IPs at perimeter firewalls and DNS resolvers
- Quarantine all inbound emails containing password-protected ZIP/RAR archives from untrusted external senders
- Search for Scheduled Tasks named 'WindowsDefenderMaintenance' created outside change windows and remove matching tasks
- Hunt for HKCU\Software\Classes\CLSID MruPidlList registry modifications
- Reset credentials for any user observed to have executed an LNK from an extracted archive
Workarounds
- Disable automatic execution of LNK files from Explorer for non-privileged users via Group Policy
- Force all archive extraction through an EDR-instrumented sandbox before access
- Disable ScriptHost (WScript/CScript) and HTA execution on user workstations where not required
Longer-term hardening
- Deploy EDR with behavioural detections for DLL sideloading by renamed AnyDesk, VMware, and Adobe binaries
- Enforce application allowlisting (WDAC or AppLocker) to prevent execution of untrusted binaries from user-writable locations
- Implement email attachment unpacking and content inspection for password-protected archives
- Segment hospital clinical networks from corporate IT and block outbound HTTPS from clinical workstations to non-allowlisted domains
- Deploy DNS filtering with reputation scoring to block access to newly-registered Ukrainian-language typosquat domains
Weaknesses (CWE) in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
CWE-427, CWE-494, CWE-506, CWE-829
Timeline of UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
- CERT-UA first tracks intrusion activity attributed to UAC-0247 targeting Ukrainian Defence Forces units.
- UAC-0247 observed deploying SPYCLOAK implant — later assessed as code-lineage precursor to AGINGFLY — against military-adjacent suppliers.
- Earliest AGINGFLY sample compiled (PE timestamp). No victim telemetry yet.
- First confirmed AGINGFLY victim: a regional oblast administration in central Ukraine. Spearphishing email posing as a health ministry procurement notice.
- Campaign expands to regional hospitals providing frontline trauma care; four hospitals confirmed compromised through a single wave of pharmacy-distributor-themed lures.
- Two civilian FPV drone assembly workshops crowdfunding for the Armed Forces of Ukraine are compromised via drone-parts purchase-order lures.
- Post-exploitation Active Directory reconnaissance (SharpHound) and credential dumping (Mimikatz) observed on hospital domain controllers.
- Exfiltration of patient records, municipal procurement documents, and drone hardware schematics confirmed by CERT-UA incident responders.
- CERT-UA publishes public advisory naming UAC-0247 and AGINGFLY, releasing IOCs and YARA rules.
- Threadlinqs Intelligence publishes TL-2026-0377 with full MITRE mapping, IOCs, and detection coverage.
- As of 2026-05-29, UAC-0247's AGINGFLY espionage campaign against Ukrainian hospitals, municipalities and FPV-drone operators remains active and undisrupted, corroborated by CERT-UA, The Record, BleepingComputer and SOC Prime (March-April 2026). No takedown, arrests or sinkholing reported; the Russia-aligned actor (SPYCLOAK lineage since 2024) persists and defenders are still told to block live C2.
Sources cited for UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian
- CERT-UA Advisory: UAC-0247 AGINGFLY Campaign
- CERT-UA UAC-0247 Actor Profile
- MITRE ATT&CK T1547.001 Registry Run Keys / Startup Folder
- MITRE ATT&CK T1574.002 Hijack Execution Flow: DLL Side-Loading
- MITRE ATT&CK T1566.001 Spearphishing Attachment
- CISA Alert on Russia-aligned Threats to Ukrainian Healthcare
- State Service of Special Communications Ukraine Threat Bulletin
More in malware
- Coordinated Campaign of 32 Malicious Chrome/Edge Productivity Extensions Conducting Surveillance and Affiliate-Fraud Traffic Redirection
- 2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm
- North Korea-Linked XCTDH/OmniStealer Campaign Uses Ethereum Transactions (HashHiding) for Covert C2 Signaling
- SilverFox (Yinhu) Fake Software Download Sites Deliver Per-Request Malware Installers and Weaken Windows Defenses
- OpenSUpdater Malware Hides Reflective Loader Inside Recompiled 7-Zip SFX Installers
Detection coverage for TL-2026-0377
As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0377 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.