Threat reportMalwareTL-2026-0389
AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnel
AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian (TL-2026-0389), also tracked as UAC-0247 Campaign, is a high-severity malware campaign, first published 2026-04-17. It is attributed to UAC-0247 (Russia) with medium confidence, affects Microsoft Windows, maps to 37 MITRE ATT&CK techniques (T1005, T1018, T1027), and is covered by 9 detection rules and 24 indicators of compromise.
- Severity
- HIGHAssessed severity
- CVEs
- 0None referenced
- Techniques
- 37MITRE ATT&CK
- Actors
- 1UAC-0247
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 24Indicators of compromise
Key facts for TL-2026-0389
- Threat ID
- TL-2026-0389
- Also known as
- UAC-0247 Campaign, AgingFly, AgingFly Implant, CERT-UA 6288271
- Severity
- HIGH
- Status
- ACTIVE
- Category
- MALWARE
- First published
- Last reviewed
- Attribution
- UAC-0247
- Attribution confidence
- MEDIUM
- Nation-state nexus
- Russia
- Motivation
- ESPIONAGE
- Target sectors
- government, local-government, healthcare, hospitals, defense, military, public-sector
- Target regions
- Ukraine, Eastern Europe
- Detection rules
- 9
- Indicators of compromise
- 24
Malware and tooling in AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
Malware and tooling: AgingFly, Chisel, ChromElevator, Ligolo-ng, RustScan, Telegram Bot API, ZAPiXDESK
How AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian works
Ukraine's CERT-UA has attributed an active malware campaign tracked as UAC-0247 deploying a new C# toolset called AgingFly against Ukrainian local governments, hospitals, and members of the defense forces. The intrusion chain begins with humanitarian-aid themed phishing emails carrying malicious .lnk shortcuts that trigger PowerShell loaders, compile C# command handlers on the infected host, steal Chromium browser credentials via the open-source ChromElevator tool, decrypt WhatsApp data via ZAPiXDESK (ZAPiDESK), and use Telegram as a Command and Control channel. At least a dozen organizations have been impacted, with follow-on tooling including RustScan, Chisel, and Ligolo-ng enabling reconnaissance, tunneling, and lateral movement.
On 2026-04-17, Ukraine's Computer Emergency Response Team (CERT-UA) published advisory 6288271 detailing an active cyberespionage campaign tracked as UAC-0247. The campaign relies on a previously undocumented modular implant named AgingFly — a C# malware family that is delivered in partially-assembled source form and compiled on the victim host after execution, sharply reducing the static signatures available for defenders and traditional antivirus engines.
Infection begins with targeted phishing emails impersonating humanitarian-aid offers, a lure explicitly tailored to Ukrainian recipients in wartime conditions. Victims are induced to download or open a malicious Windows shortcut (.lnk) file; when executed, the shortcut invokes PowerShell, which retrieves follow-on loader stages. The loaders stage AgingFly source/assemblies on disk, invoke the in-box C# compiler (csc.exe / Roslyn) to produce a working implant, and then launch it. This 'Compile After Delivery' (T1027.004) design is deliberately chosen to frustrate signature-based detection and allow per-victim polymorphism.
Once running, AgingFly provides remote operators with a full-featured remote access capability: arbitrary command execution, file theft, screen capture, keystroke logging, and on-demand delivery of additional payloads. Operators update configuration and rotate command-and-control endpoints through Telegram, using the messaging platform's public API infrastructure as a resilient covert channel (T1102 Web Service). PowerShell scripts are used in-band to refresh C2 routing and pull next-stage tooling.
The campaign layers well-known open-source offensive tooling on top of the custom implant. Chromium browser credentials and cookies are exfiltrated using ChromElevator (xaitax/Chrome-App-Bound-Encryption-Decryption), a public PoC that defeats Chrome's App-Bound Encryption to recover saved passwords and session cookies. WhatsApp desktop databases are dumped and decrypted using ZAPiXDESK (kraftdenker/ZAPiXDESK), giving operators access to victim chat history. Network reconnaissance is performed with RustScan (bee-san/RustScan), while Ligolo-ng and Chisel (jpillora/chisel) provide reverse tunnels and pivoting across segmented Ukrainian government networks.
CERT-UA reports the campaign has already impacted at least a dozen Ukrainian organizations — local government bodies and hospitals are explicitly named, and intelligence indicators suggest members of the Ukrainian defense forces have also been targeted. SentinelLabs, in its Week 16 roundup, corroborates the CERT-UA findings and publishes an attack-chain diagram. The combination of Ukrainian-government targeting, espionage-grade tradecraft, exfiltration of WhatsApp/browser secrets and defense-sector interest is consistent with the broader pattern of Russia-aligned intrusion sets active in Ukraine since 2022; however, CERT-UA has not (as of publication) issued a specific nation-state attribution beyond the UAC-0247 cluster label.
Defenders should treat this campaign as an active, high-severity threat: it produces few traditional IOCs (the implant is recompiled per host, C2 rides on a legitimate SaaS, and most of the post-exploitation toolset is open-source). Detection must focus on behavioral telemetry — .lnk → PowerShell chains, csc.exe / Roslyn compilation from unusual parent processes, Chrome DPAPI / App-Bound key extraction, WhatsApp sqlite/cryptkey reads, and outbound traffic to api.telegram.org from non-browser processes.
MITRE ATT&CK techniques used in TL-2026-0389
Collection
T1005 Data from Local System; T1056.001 Input Capture: Keylogging; T1113 Screen Capture; T1560 Archive Collected Data
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery; T1082 System Information Discovery; T1083 File and Directory Discovery
Defense Evasion
T1027 Obfuscated Files or Information; T1027.004 Compile After Delivery; T1036 Masquerading; T1127 Trusted Developer Utilities Proxy Execution; T1140 Deobfuscate/Decode Files or Information
Exfiltration
T1041 Exfiltration Over C2 Channel; T1567 Exfiltration Over Web Service
Execution
T1059 Command and Scripting Interpreter; T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204 User Execution; T1204.002 Malicious File
Command and Control
T1071.001 Application Layer Protocol: Web Protocols; T1102 Web Service; T1102.002 Bidirectional Communication; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Credential Access
T1539 Steal Web Session Cookie; T1552 Unsecured Credentials; T1555 Credentials from Password Stores; T1555.003 Credentials from Web Browsers
Initial Access
T1566 Phishing; T1566.001 Spearphishing Attachment; T1566.002 Spearphishing Link
Lateral Movement
command-and-control
Resource Development
T1587.001 Develop Capabilities: Malware; T1588.002 Obtain Capabilities: Tool
Affected products and versions in AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
- Microsoft — Windows
Vulnerable versions: 10; 11; Server 2016; Server 2019; Server 2022 - Google — Chrome
Vulnerable versions: <127 without App-Bound Encryption enforcement
Fixed in: 127+ - Meta — WhatsApp Desktop
Vulnerable versions: Legacy builds with accessible local crypt keys - Microsoft — .NET Framework / .NET
Vulnerable versions: All supported versions (csc.exe / Roslyn abused for in-host compilation)
Remediation for AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
Patches
- Ensure Chromium-based browsers are updated to versions enforcing App-Bound Encryption (Chrome 127+); ChromElevator targets older/unprotected profiles
- Patch WhatsApp Desktop to the latest version — legacy builds expose plaintext-accessible cryptkeys that ZAPiXDESK relies on
- Apply latest Microsoft .NET and Windows cumulative updates
Immediate actions
- Block execution of Windows .lnk attachments originating from email at mail gateway and EDR policy
- Alert on any non-browser process resolving or connecting to api.telegram.org or t.me
- Alert on csc.exe, csc.exe /target:exe, or Microsoft.CSharp.CSharpCodeProvider invocations with parents of powershell.exe, wscript.exe, cscript.exe, or Office apps
- Block the public GitHub release assets of ChromElevator, ZAPiXDESK, Chisel, Ligolo-ng, and RustScan at web proxy if no legitimate business use
- Search historical telemetry for .lnk files dropped by email clients executing powershell.exe with encoded or downloader commands
- Hunt for Chrome DPAPI master key reads and App-Bound Encryption key file (Local State) reads by processes other than chrome.exe / msedge.exe
Workarounds
- Disable csc.exe / Roslyn compilation on endpoints that do not need it via Windows Defender Application Control (WDAC) code-integrity policy
- Block execution of .lnk files from user-writable locations (Downloads, Outlook temp, Teams Downloads) using AppLocker / WDAC
- Restrict outbound access to api.telegram.org at corporate firewall for endpoints with no legitimate need
- Disable WhatsApp Desktop on high-sensitivity workstations or move chat to managed collaboration platforms
Longer-term hardening
- Deploy an EDR platform with in-memory .NET assembly inspection and script-block logging coverage
- Enable PowerShell module, script-block, and transcription logging across all Windows endpoints
- Enable Windows AMSI and ensure anti-tamper settings prevent AMSI bypass
- Roll out attack-surface-reduction (ASR) rules: Block executable content from email, Block Office children, Block JavaScript/VBScript launching executables
- Segment hospital and local-government networks and restrict outbound egress to a proxy-enforced allowlist to blunt Chisel/Ligolo-ng tunnels
- Mandate rotation of browser-saved credentials following any confirmed AgingFly incident and force SSO re-auth for all sensitive apps
Weaknesses (CWE) in AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
Timeline of AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
- Earliest suspected AgingFly / UAC-0247 activity based on CERT-UA victim telemetry — humanitarian-aid themed spearphishing emails delivered to Ukrainian local governments and hospitals
- At least a dozen Ukrainian organizations impacted; CERT-UA opens formal investigation into the UAC-0247 cluster
- Indicators emerge that members of Ukraine's defense forces are among the targeted victims, elevating strategic priority of the investigation
- CERT-UA investigators complete mapping of the AgingFly execution chain — .lnk -> PowerShell loaders -> in-host C# compilation -> RAT with Telegram C2, ChromElevator, ZAPiXDESK, RustScan, Ligolo-ng, Chisel
- Threadlinqs Intelligence publishes TL-2026-0389 with full MITRE ATT&CK mapping, IOCs, detections, and attack simulations
- SentinelLabs publishes a Week 16 roundup corroborating the CERT-UA findings and reproducing the attack-chain diagram
- CERT-UA publishes advisory article 6288271 detailing the UAC-0247 AgingFly malware campaign and TTPs
- As of 2026-05-29, the UAC-0247 AgingFly espionage campaign against Ukrainian government, hospitals, and defense personnel remains active and expanding, with CERT-UA (advisory 6288271) and corroborating reporting (BleepingComputer, Recorded Future, SOC Prime) describing ongoing March-April 2026 intrusions. No takedown, sinkhole, arrest, or patch exists; the C# implant uses behavioral-only detection and resilient Telegram/WebSocket C2, so the Russia-aligned actor stays a live threat.
Sources cited for AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian
- CERT-UA Advisory 6288271 — UAC-0247 / AgingFly Campaign
- SentinelLabs — The Good, the Bad and the Ugly in Cybersecurity Week 16
- ChromElevator — Chrome App-Bound Encryption Decryption (xaitax)
- ZAPiXDESK — WhatsApp Desktop data decryption (kraftdenker)
- RustScan — Fast port scanner (bee-san)
- Ligolo-ng — Kali Tools documentation
- Chisel — Fast TCP/UDP tunnel over HTTP (jpillora)
- MITRE ATT&CK — T1027.004 Compile After Delivery
- MITRE ATT&CK — T1102 Web Service (Telegram C2)
- MITRE ATT&CK — T1555.003 Credentials from Web Browsers
Detection coverage for TL-2026-0389
As of 2026-04-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0389 across Splunk SPL, Microsoft KQL and Sigma, covering 24 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.