UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian Hospitals, Local Government, and FPV Drone Operators

UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian (TL-2026-0377), also tracked as AGINGFLY Campaign, is a high-severity malware campaign scored CVSS 8.1, first published 2026-04-16. It is attributed to UAC-0247 (Russia) with high confidence, affects Microsoft Windows, maps to 27 MITRE ATT&CK techniques (T1003, T1027, T1036), and is covered by 9 detection rules and 24 indicators of compromise.

Key facts for TL-2026-0377

Threat ID
TL-2026-0377
Also known as
AGINGFLY Campaign, Operation AGINGFLY
Severity
HIGH
CVSS
8.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L)
Status
ACTIVE
Category
MALWARE
First published
2026-04-16
Last reviewed
2026-04-16
Attribution
UAC-0247
Attribution confidence
HIGH
Nation-state nexus
Russia
Motivation
ESPIONAGE
Target sectors
healthcare, government, defense-industrial-base, critical-infrastructure, non-profit
Target regions
Ukraine, Eastern Europe
Detection rules
9
Indicators of compromise
24

Malware and tooling in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

Malware and tooling: AGINGFLY, SPYCLOAK, Mimikatz, SharpHound

Russia-aligned threat actor UAC-0247 is conducting a targeted spearphishing campaign delivering a previously undocumented backdoor named AGINGFLY against Ukrainian critical infrastructure. CERT-UA confirms compromises across regional hospitals, municipal administrations, and civilian FPV (first-person-view) drone operator workshops, with objectives spanning espionage, credential theft, and network reconnaissance for follow-on operations. The malware's custom C2 protocol, LNK-based delivery chain, and use of legitimate Ukrainian-language lures (procurement invoices, medical supply notices, drone parts purchase orders) demonstrate the operator's deep familiarity with the target environment and its operational tempo.

How UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian works

On 15 April 2026, CERT-UA published an advisory attributing a cluster of intrusions against Ukrainian healthcare providers, oblast-level government bodies, and non-state FPV drone production workshops to UAC-0247, a Russia-aligned intrusion set first tracked by CERT-UA in late 2024 for operations against Ukrainian Defence Forces and military-adjacent suppliers. The current campaign introduces AGINGFLY, a bespoke .NET backdoor that had not been observed prior to February 2026 and which CERT-UA assesses with high confidence to be developed and operated exclusively by UAC-0247.

Initial access is obtained through spearphishing emails written in fluent Ukrainian, typically impersonating procurement officers, pharmacy distributors, or drone component suppliers. Messages deliver password-protected ZIP or RAR archives containing a decoy PDF and a Windows shortcut (.LNK) file. When the shortcut is executed, it invokes forfiles.exe or cmd.exe to launch a packaged HTA that stages AGINGFLY via a DLL sideloaded by a renamed, legitimate signed binary (AnyDesk.exe, vmnat.exe, or Adobe components). The loader decrypts AGINGFLY from an RC4-encrypted blob embedded in an accompanying .dat file and injects it into the host process.

AGINGFLY provides its operators with a capable but relatively compact feature set: arbitrary command execution, secure file upload and download, process listing and termination, screenshot capture, clipboard monitoring, and an in-memory credential harvester that scrapes browser login data, WiFi profiles, and Windows DPAPI master keys. Persistence is achieved either through a Scheduled Task named 'WindowsDefenderMaintenance' or through COM hijacking of the MruPidlList key under HKCU, depending on operator discretion. Command-and-control traffic is tunnelled over HTTPS to compromised Ukrainian small-business websites acting as redirectors, with final hop infrastructure hosted on bulletproof providers in Russia and Belarus. Beacon cadence is randomised between 45 and 180 seconds, with JSON payloads RC4-encrypted using a per-implant key negotiated via a custom handshake.

CERT-UA reports at least nine confirmed victims as of 14 April 2026: three oblast-level municipal administrations (including Poltava and Sumy), four regional hospitals involved in frontline trauma care, and two civilian FPV drone assembly workshops that have publicly crowdfunded for the Armed Forces of Ukraine. Post-exploitation activity observed to date includes staging of Mimikatz, enumeration of Active Directory via SharpHound, and exfiltration of patient record databases, municipal procurement documents, and drone hardware schematics. No destructive or ransomware activity has been observed, consistent with UAC-0247's espionage-focused mission.

Attribution to UAC-0247 (and by extension to a Russia-aligned intelligence-gathering effort) is based on overlapping code lineage between AGINGFLY and the earlier SPYCLOAK implant used in 2025 Defence Forces intrusions, reuse of specific registry persistence tradecraft, phishing infrastructure registered through the same set of bulletproof registrars, and CERT-UA's first-party victim telemetry. Defenders should prioritise email gateway inspection for password-protected archives containing LNKs, application allowlisting to break DLL sideloading chains, and EDR detections for the listed persistence mechanisms.

MITRE ATT&CK techniques used in TL-2026-0377

Credential Access

T1003 OS Credential Dumping; T1552 Unsecured Credentials; T1555 Credentials from Password Stores

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1055 Process Injection; T1574 Hijack Execution Flow

Exfiltration

T1041 Exfiltration Over C2 Channel

Persistence

T1053 Scheduled Task/Job; T1546 Event Triggered Execution

Execution

T1059 Command and Scripting Interpreter; T1204 User Execution

Command and Control

T1071 Application Layer Protocol; T1090 Proxy; T1573 Encrypted Channel

Discovery

T1082 System Information Discovery; T1087 Account Discovery; T1482 Domain Trust Discovery

Collection

T1113 Screen Capture; T1115 Clipboard Data; T1560 Archive Collected Data

stealth

T1218 System Binary Proxy Execution

Initial Access

T1566 Phishing

Resource Development

T1583 Acquire Infrastructure; T1584 Compromise Infrastructure; T1587 Develop Capabilities

Reconnaissance

T1589 Gather Victim Identity Information

Affected products and versions in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

  • Microsoft — Windows
    Vulnerable versions: 10; 11; Server 2019; Server 2022
  • Multi-vendor — Legitimate signed binaries abused for DLL sideloading (AnyDesk, VMware Workstation, Adobe Reader components)
    Vulnerable versions: abused as loader host, not vulnerable products

Remediation for UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

Patches

  • No CVE-based patch applies; this is a social-engineering-led malware campaign rather than a software vulnerability

Immediate actions

  • Block AGINGFLY C2 domains and IPs at perimeter firewalls and DNS resolvers
  • Quarantine all inbound emails containing password-protected ZIP/RAR archives from untrusted external senders
  • Search for Scheduled Tasks named 'WindowsDefenderMaintenance' created outside change windows and remove matching tasks
  • Hunt for HKCU\Software\Classes\CLSID MruPidlList registry modifications
  • Reset credentials for any user observed to have executed an LNK from an extracted archive

Workarounds

  • Disable automatic execution of LNK files from Explorer for non-privileged users via Group Policy
  • Force all archive extraction through an EDR-instrumented sandbox before access
  • Disable ScriptHost (WScript/CScript) and HTA execution on user workstations where not required

Longer-term hardening

  • Deploy EDR with behavioural detections for DLL sideloading by renamed AnyDesk, VMware, and Adobe binaries
  • Enforce application allowlisting (WDAC or AppLocker) to prevent execution of untrusted binaries from user-writable locations
  • Implement email attachment unpacking and content inspection for password-protected archives
  • Segment hospital clinical networks from corporate IT and block outbound HTTPS from clinical workstations to non-allowlisted domains
  • Deploy DNS filtering with reputation scoring to block access to newly-registered Ukrainian-language typosquat domains

Weaknesses (CWE) in UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

CWE-427, CWE-494, CWE-506, CWE-829

Timeline of UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

  • CERT-UA first tracks intrusion activity attributed to UAC-0247 targeting Ukrainian Defence Forces units.
  • UAC-0247 observed deploying SPYCLOAK implant — later assessed as code-lineage precursor to AGINGFLY — against military-adjacent suppliers.
  • Earliest AGINGFLY sample compiled (PE timestamp). No victim telemetry yet.
  • First confirmed AGINGFLY victim: a regional oblast administration in central Ukraine. Spearphishing email posing as a health ministry procurement notice.
  • Campaign expands to regional hospitals providing frontline trauma care; four hospitals confirmed compromised through a single wave of pharmacy-distributor-themed lures.
  • Two civilian FPV drone assembly workshops crowdfunding for the Armed Forces of Ukraine are compromised via drone-parts purchase-order lures.
  • Post-exploitation Active Directory reconnaissance (SharpHound) and credential dumping (Mimikatz) observed on hospital domain controllers.
  • Exfiltration of patient records, municipal procurement documents, and drone hardware schematics confirmed by CERT-UA incident responders.
  • CERT-UA publishes public advisory naming UAC-0247 and AGINGFLY, releasing IOCs and YARA rules.
  • Threadlinqs Intelligence publishes TL-2026-0377 with full MITRE mapping, IOCs, and detection coverage.
  • As of 2026-05-29, UAC-0247's AGINGFLY espionage campaign against Ukrainian hospitals, municipalities and FPV-drone operators remains active and undisrupted, corroborated by CERT-UA, The Record, BleepingComputer and SOC Prime (March-April 2026). No takedown, arrests or sinkholing reported; the Russia-aligned actor (SPYCLOAK lineage since 2024) persists and defenders are still told to block live C2.

Sources cited for UAC-0247 Deploys Novel AGINGFLY Backdoor Against Ukrainian

More in malware

Detection coverage for TL-2026-0377

As of 2026-04-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0377 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat weather, live.

Every square is one real report, mapped to MITRE ATT&CK and shipped with Splunk SPL, Microsoft KQL and Sigma detections you can copy.

Every threat in the corpus, newest first.

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats