AGEWHEEZE is a Go-based remote access trojan (RAT) / remote administration tool classified by CERT-UA as a multifunctional malware family used in a phishing campaign attributed to UAC-0255. In the reported activity, attackers impersonated Ukraine’s CERT-UA on March 26-27, 2026 and targeted Ukrainian government organizations, medical centers and healthcare providers, financial institutions, security firms, educational institutions, and software development companies. Delivery relied on phishing emails and a spoofed website, cert-ua[.]tech, that mimicked the legitimate CERT-UA site and directed victims to download password-protected archives such as "CERT_UA_protection_tool.zip" and "protection_tool.zip" hosted on Files.fm; some reporting also cited the sender address incidents@cert-ua[.]tech.
Observed AGEWHEEZE capabilities include command execution, file and directory management, screenshot capture or screen content transmission, mouse and keyboard input emulation, clipboard access, process listing and termination, service control, URL opening, terminal command execution, and host actions such as shutdown, restart, or lock. It communicates with command-and-control infrastructure over WebSockets, including wss://54[.]36.237.92:8443, hosted on OVH infrastructure. CERT-UA reporting also noted an exposed management panel titled "The Cult" and Russian-language elements on the infrastructure.
For persistence, AGEWHEEZE was observed installing under %APPDATA%\SysSvc\SysSvc.exe or %APPDATA%\service\service.exe, creating autorun entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run, and creating scheduled tasks named "SvcHelper" and "CoreService"; reporting also states it may use the Startup directory. Additional indicators directly mentioned in the reporting include cert-ua[.]tech, creepy[.]ltd, hiddify.creepy[.]ltd, panel.creepy[.]ltd, and sample SHA-256 hashes 5f16463f5c463f5f2f69f31c6ce7d3040d07876156a265b5521737f1c7a2a9b3 and 342cf215d7599a65b23398038f943f516b0bd649926e21427d8e028fffec93d7. CERT-UA assessed the campaign’s real-world impact as limited, with only a small number of infected personal devices belonging to educational institution staff identified.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
This operation aimed to distribute the AGEWHEEZE remote access tool to a wide range of potential victims.
19 distinct techniques documented for this family, organized by ATT&CK tactic.
The attackers created a fake website (cert-ua[.]tech) mimicking the real CERT-UA site to spread the fake “security tool” that is actually AGEWHEEZE malware.
Upon installation, this tool deployed AGEWHEEZE, a multifunctional malware capable of command execution, file management, screen capture, and ensuring persistence through registry or scheduled tasks.
The malware then writes registry entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and registers scheduled tasks named “SvcHelper” and “CoreService” to make sure it keeps running even after the machine is restarted.
Upon installation, this tool deployed AGEWHEEZE, a multifunctional malware capable of command execution, file management, screen capture...
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
Upon installation, this tool deployed AGEWHEEZE, a multifunctional malware capable of command execution, file management, screen capture, and ensuring persistence through registry or scheduled tasks.
The malware then writes registry entries under HKCU\Software\Microsoft\Windows\CurrentVersion\Run and registers scheduled tasks named “SvcHelper” and “CoreService” to make sure it keeps running even after the machine is restarted.
Upon installation, this tool deployed AGEWHEEZE, a multifunctional malware capable of command execution, file management, screen capture, and ensuring persistence through registry or scheduled tasks.
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
AGEWHEEZE supports command execution, file management, screen capture, input control, and process/service management.
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
Upon installation, this tool deployed AGEWHEEZE, a multifunctional malware capable of command execution, file management, screen capture...
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
The malware packs a broad set of capabilities — it can capture screenshots, simulate mouse clicks and keyboard input, manage files and directories, list and kill active processes, control system services, read and write clipboard data, open URLs, run terminal commands, and even perform power actions like shutdown, restart, or lock.
24 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A multifunctional remote access malware capable of command execution, file management, screen capture, and persistence via registry modifications or scheduled tasks.
A Go-based remote access trojan delivered via phishing emails and a cloned CERT-UA website. It installs itself in AppData, establishes persistence via Run registry keys and scheduled tasks, connects to a C2 server over WebSockets on port 8443, and supports screenshots, input simulation, file and process management, service control, clipboard access, URL opening, terminal command execution, and power actions.
AGEWHEEZE is a multifunctional remote access tool that gives attackers control over infected systems. It supports command execution, file management, screen capture, input control, process and service management, persistence via registry/startup/scheduled tasks, WebSocket-based C2 communications, clipboard theft, and system action control.
A Go-based remote access trojan distributed via phishing emails masquerading as CERT-UA security software. It communicates with an external server over WebSockets and supports command execution, file operations, clipboard modification, mouse and keyboard emulation, screenshot capture, and process and service management. It establishes persistence via scheduled tasks, Windows Registry modification, or the Startup directory.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.