Executive Summary
In late March 2026, the threat actor group UAC-0255 launched a phishing campaign impersonating the Computer Emergency Response Team of Ukraine (CERT-UA). The attackers sent emails on March 26 and 27, 2026, posing as CERT-UA to distribute a password-protected ZIP archive hosted on Files.fm, urging recipients to install the 'specialized software.' The ZIP file ('CERT_UA_protection_tool.zip') is designed to download malware packaged as security software from the agency. The targets of the campaign included state organizations, medical centers, security companies, educational institutions, financial institutions, and software development companies. Some of the emails were sent from the email address 'incidents@cert-ua[.]tech.'
Why This Matters Now
Attack Path Analysis
The attack began with phishing emails impersonating CERT-UA, leading to the download and execution of the AGEWHEEZE malware. The malware established persistence through scheduled tasks and registry modifications, enabling the attacker to escalate privileges. Utilizing AGEWHEEZE's capabilities, the attacker moved laterally within the network, accessing additional systems. The malware communicated with a command-and-control server over WebSockets, allowing remote control of infected devices. Sensitive data was exfiltrated to the attacker's server. The attack concluded with the potential for further malicious actions, though specific impacts were not detailed.
Kill Chain Progression
Initial Compromise
Description
Phishing emails impersonating CERT-UA were sent to targets, leading recipients to download and execute the AGEWHEEZE malware.
MITRE ATT&CK® Techniques
Spearphishing Attachment
User Execution: Malicious File
Ingress Tool Transfer
Command and Scripting Interpreter: PowerShell
Application Layer Protocol: Web Protocols
Masquerading: Match Legitimate Name or Location
Hijack Execution Flow: DLL Side-Loading
Process Injection: Dynamic-link Library Injection
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Identity Verification and Authentication
Control ID: Identity Pillar
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Government Administration
CERT-UA impersonation campaign targeting government entities with AGEWHEEZE remote access trojan poses critical threats to classified systems and administrative operations requiring enhanced egress security.
Computer/Network Security
Cybersecurity firms face reputational damage and client trust erosion when threat actors impersonate security agencies to deploy remote access trojans, demanding stronger threat detection capabilities.
Financial Services
Banking sector vulnerable to AGEWHEEZE trojan's lateral movement and data exfiltration capabilities, requiring zero trust segmentation and encrypted traffic monitoring for regulatory compliance protection.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations from remote access trojans enabling patient data exfiltration, necessitating multicloud visibility and anomaly detection systems implementation.
Sources
- CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emailshttps://thehackernews.com/2026/04/cert-ua-impersonation-campaign-spread.htmlVerified
- UAC-0255 Uses AGEWHEEZE in Fake CERT-UA Alertshttps://socprime.com/active-threats/cyberattack-uac-0255-from-cert-ua/Verified
- Hackers Impersonate CERT-UA To Plant AGEWHEEZE Remote Trojanhttps://thecyberexpress.com/hackers-impersonate-cert-ua-agewheeze-rat/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and controlled egress policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix Zero Trust CNSF primarily focuses on network segmentation and traffic control, it may not directly prevent initial compromises via phishing emails.
Control: Zero Trust Segmentation
Mitigation: By enforcing strict segmentation, Aviatrix Zero Trust CNSF could likely limit the attacker's ability to escalate privileges across different network segments.
Control: East-West Traffic Security
Mitigation: Aviatrix Zero Trust CNSF would likely restrict lateral movement by enforcing east-west traffic controls, thereby limiting the attacker's ability to access additional systems.
Control: Multicloud Visibility & Control
Mitigation: With enhanced visibility, Aviatrix Zero Trust CNSF could likely detect and limit unauthorized command-and-control communications, reducing the attacker's remote control capabilities.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Zero Trust CNSF would likely limit data exfiltration by enforcing strict egress policies, thereby reducing the attacker's ability to transmit sensitive data externally.
By limiting lateral movement and data exfiltration, Aviatrix Zero Trust CNSF could likely reduce the overall impact and blast radius of the attack.
Impact at a Glance
Affected Business Functions
- Email Communications
- IT Security Operations
- Data Integrity
- Regulatory Compliance
Estimated downtime: 1 days
Estimated loss: N/A
Potential exposure of sensitive organizational data due to remote access capabilities of AGEWHEEZE malware.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict lateral movement within the network.
- • Deploy Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Utilize Threat Detection & Anomaly Response systems to identify and respond to unusual activities indicative of command-and-control communications.
- • Enforce East-West Traffic Security to detect and prevent unauthorized internal communications between workloads.
- • Apply Inline IPS (Suricata) to inspect and block malicious payloads during the initial compromise phase.



