UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian Hospitals, Local Government, and FPV Drone Operators — Threadlinqs Intelligence
As of 2026-05-30, UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian Hospitals, Local Government, and FPV Drone Operators is a high-severity malware threat attributed to UAC-0247 (Russia), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 24 indicators of compromise.
Threat ID: TL-2026-0377 · Severity: HIGH · CVSS: 8.1 · Status: ACTIVE · Category: MALWARE
Attribution: UAC-0247 · Russia · ESPIONAGE
Russia-aligned threat actor UAC-0247 is conducting a targeted spearphishing campaign delivering a previously undocumented backdoor named AGINGFLY against Ukrainian critical infrastructure. CERT-UA
On 15 April 2026, CERT-UA published an advisory attributing a cluster of intrusions against Ukrainian healthcare providers, oblast-level government bodies, and non-state FPV drone production workshops to UAC-0247, a Russia-aligned intrusion set first tracked by CERT-UA in late 2024 for operations against Ukrainian Defence Forces and military-adjacent suppliers. The current campaign introduces AGINGFLY, a bespoke .NET backdoor that had not been observed prior to February 2026 and which CERT-UA assesses with high confidence to be developed and operated exclusively by UAC-0247.
Initial access is obtained through spearphishing emails written in fluent Ukrainian, typically impersonating procurement officers, pharmacy distributors, or drone component suppliers. Messages deliver password-protected ZIP or RAR archives containing a decoy PDF and a Windows shortcut (.LNK) file. When the shortcut is executed, it invokes forfiles.exe or cmd.exe to launch a packaged HTA that stages AGINGFLY via a DLL sideloaded by a renamed, legitimate signed binary (AnyDesk.exe, vmnat.exe, or Adobe components). The loader decrypts AGINGFLY from an RC4-encrypted blob embedded in an accompanying .dat file and injects it into the host process.
AGINGFLY provides its operators with a capable but relatively compact feature set: arbitrary command execution, secure file upload and download, process listing and termination, screenshot capture, clipboard monitoring, and an in-memory credential harvester that scrapes browser login data, WiFi profiles, and Windows DPAPI master keys. Persistence is achieved either through a Scheduled Task named 'WindowsDefenderMaintenance' or through COM hijacking of the MruPidlList key under HKCU, depending on operator discretion. Command-and-control traffic is tunnelled over HTTPS to compromised Ukrainian small-business websites acting as redirectors, with final hop infrastructure hosted on bulletproof providers in Russia and Belarus. Beacon cadence is randomised between 45 and 180 seconds, with JSON payloads RC4-encrypted using a per-implant key negotiated via a custom handshake.
CERT-UA reports at least nine confirmed victims as of 14 April 2026: three oblast-level municipal administrations (including Poltava and Sumy), four regional hospitals involved in frontline trauma care, and two civilian FPV drone assembly workshops that have publicly crowdfunded for the Armed Forces of Ukraine. Post-exploitation activity observed to date includes staging of Mimikatz, enumeration of Active Directory via SharpHound, and exfiltration of patient record databases, municipal procurement documents, and drone hardware schematics. No destructive or ransomware activity has been observed, consistent with UAC-0247's espionage-focused mission.
Attribution to UAC-0247 (and by extension to a Russia-aligned intelligence-gathering effort) is based on overlapping code lineage between AGINGFLY and the earlier SPYCLOAK implant used in 2025 Defence Forces intrusions, reuse of specific registry persistence tradecraft, phishing infrastructure registered through the same set of bulletproof registrars, and CERT-UA's first-party victim telemetry. Defenders should prioritise email gateway inspection for password-protected archives containing LNKs, application allowlisting to break DLL sideloading chains, and EDR detections for the listed persistence mechanisms.
Weaknesses (CWE)
CWE-427, CWE-494, CWE-506, CWE-829
Target sectors: healthcare, government, defense-industrial-base, critical-infrastructure, non-profit
Target regions: Ukraine, Eastern Europe
Detections & IOCs
As of 2026-07-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 24 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1589, T1583, T1584, T1587, T1566, T1204, T1059, T1059, T1218, T1053