# AgingFly Malware Campaign (UAC-0247) Targeting Ukrainian Governments, Hospitals, and Defense Personnel

> Ukraine's CERT-UA has attributed an active malware campaign tracked as UAC-0247 deploying a new C# toolset called AgingFly against Ukrainian local governments, hospitals, and members of the defense forces. The intrusion chain begins with humanitarian-aid themed phishing emails carrying malicious .lnk shortcuts that trigger PowerShell loaders, compile C# command handlers on the infected host, steal Chromium browser credentials via the open-source ChromElevator tool, decrypt WhatsApp data via ZAPiXDESK (ZAPiDESK), and use Telegram as a Command and Control channel. At least a dozen organizations have been impacted, with follow-on tooling including RustScan, Chisel, and Ligolo-ng enabling reconnaissance, tunneling, and lateral movement.

- **Published:** 2026-04-17T12:00:00Z
- **Last reviewed:** 2026-04-17T12:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0389
- **ID:** TL-2026-0389
- **Severity:** HIGH
- **Category:** MALWARE
- **Status:** ACTIVE
- **Actor:** UAC-0247 (Russia)
- **Detections:** 9 · **IOCs:** 24 (full data via the Threadlinqs MCP server — Purple tier)

## Description

On 2026-04-17, Ukraine's Computer Emergency Response Team (CERT-UA) published advisory 6288271 detailing an active cyberespionage campaign tracked as UAC-0247. The campaign relies on a previously undocumented modular implant named AgingFly — a C# malware family that is delivered in partially-assembled source form and compiled on the victim host after execution, sharply reducing the static signatures available for defenders and traditional antivirus engines.

Infection begins with targeted phishing emails impersonating humanitarian-aid offers, a lure explicitly tailored to Ukrainian recipients in wartime conditions. Victims are induced to download or open a malicious Windows shortcut (.lnk) file; when executed, the shortcut invokes PowerShell, which retrieves follow-on loader stages. The loaders stage AgingFly source/assemblies on disk, invoke the in-box C# compiler (csc.exe / Roslyn) to produce a working implant, and then launch it. This 'Compile After Delivery' (T1027.004) design is deliberately chosen to frustrate signature-based detection and allow per-victim polymorphism.

Once running, AgingFly provides remote operators with a full-featured remote access capability: arbitrary command execution, file theft, screen capture, keystroke logging, and on-demand delivery of additional payloads. Operators update configuration and rotate command-and-control endpoints through Telegram, using the messaging platform's public API infrastructure as a resilient covert channel (T1102 Web Service). PowerShell scripts are used in-band to refresh C2 routing and pull next-stage tooling.

The campaign layers well-known open-source offensive tooling on top of the custom implant. Chromium browser credentials and cookies are exfiltrated using ChromElevator (xaitax/Chrome-App-Bound-Encryption-Decryption), a public PoC that defeats Chrome's App-Bound Encryption to recover saved passwords and session cookies. WhatsApp desktop databases are dumped and decrypted using ZAPiXDESK (kraftdenker/ZAPiXDESK), giving operators access to victim chat history. Network reconnaissance is performed with RustScan (bee-san/RustScan), while Ligolo-ng and Chisel (jpillora/chisel) provide reverse tunnels and pivoting across segmented Ukrainian government networks.

CERT-UA reports the campaign has already impacted at least a dozen Ukrainian organizations — local government bodies and hospitals are explicitly named, and intelligence indicators suggest members of the Ukrainian defense forces have also been targeted. SentinelLabs, in its Week 16 roundup, corroborates the CERT-UA findings and publishes an attack-chain diagram. The combination of Ukrainian-government targeting, espionage-grade tradecraft, exfiltration of WhatsApp/browser secrets and defense-sector interest is consistent with the broader pattern of Russia-aligned intrusion sets active in Ukraine since 2022; however, CERT-UA has not (as of publication) issued a specific nation-state attribution beyond the UAC-0247 cluster label.

Defenders should treat this campaign as an active, high-severity threat: it produces few traditional IOCs (the implant is recompiled per host, C2 rides on a legitimate SaaS, and most of the post-exploitation toolset is open-source). Detection must focus on behavioral telemetry — .lnk → PowerShell chains, csc.exe / Roslyn compilation from unusual parent processes, Chrome DPAPI / App-Bound key extraction, WhatsApp sqlite/cryptkey reads, and outbound traffic to api.telegram.org from non-browser processes.

## MITRE ATT&CK

- T1566 Phishing
- T1566.001 Spearphishing Attachment
- T1566.002 Spearphishing Link
- T1204 User Execution
- T1204.002 Malicious File
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1059.005 Visual Basic
- T1059.003 Windows Command Shell
- T1027 Obfuscated Files or Information
- T1027.004 Compile After Delivery
- T1140 Deobfuscate/Decode Files or Information
- T1036 Masquerading
- T1127 Trusted Developer Utilities Proxy Execution
- T1555 Credentials from Password Stores
- T1555.003 Credentials from Web Browsers
- T1539 Steal Web Session Cookie
- T1552 Unsecured Credentials
- T1046 Network Service Discovery
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1018 Remote System Discovery
- T1572 Protocol Tunneling
- T1570 Lateral Tool Transfer
- T1005 Data from Local System
- T1113 Screen Capture
- T1056.001 Input Capture: Keylogging
- T1560 Archive Collected Data
- T1102 Web Service
- T1102.002 Bidirectional Communication
- T1071.001 Application Layer Protocol: Web Protocols
- T1105 Ingress Tool Transfer
- T1573 Encrypted Channel
- T1041 Exfiltration Over C2 Channel
- T1567 Exfiltration Over Web Service
- T1588.002 Obtain Capabilities: Tool
- T1587.001 Develop Capabilities: Malware

## Sources

- [CERT-UA Advisory 6288271 — UAC-0247 / AgingFly Campaign](https://cert.gov.ua/article/6288271)
- [SentinelLabs — The Good, the Bad and the Ugly in Cybersecurity Week 16](https://www.sentinelone.com/blog/the-good-the-bad-and-the-ugly-in-cybersecurity-week-16-7/)
- [ChromElevator — Chrome App-Bound Encryption Decryption (xaitax)](https://github.com/xaitax/Chrome-App-Bound-Encryption-Decryption)
- [ZAPiXDESK — WhatsApp Desktop data decryption (kraftdenker)](https://github.com/kraftdenker/ZAPiXDESK)
- [RustScan — Fast port scanner (bee-san)](https://github.com/bee-san/RustScan)
- [Ligolo-ng — Kali Tools documentation](https://www.kali.org/tools/ligolo-ng/)
- [Chisel — Fast TCP/UDP tunnel over HTTP (jpillora)](https://github.com/jpillora/chisel)
- [MITRE ATT&CK — T1027.004 Compile After Delivery](https://attack.mitre.org/techniques/T1027/004/)
- [MITRE ATT&CK — T1102 Web Service (Telegram C2)](https://attack.mitre.org/techniques/T1102/)
- [MITRE ATT&CK — T1555.003 Credentials from Web Browsers](https://attack.mitre.org/techniques/T1555/003/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0389
