Attackers spoofed Ukraine's Computer Emergency Response Team in a phishing campaign aimed at delivering the AGEWHEEZE remote access trojan. The activity targeted a broad cross-section of Ukrainian organizations, including government entities, healthcare providers, financial institutions, security firms, educational institutions, and software development companies.
Reporting indicates the campaign was observed between March 26 and 27 and relied on fraudulent messages impersonating CERT-UA to trick recipients into opening malicious content. The operation appears designed to steal access and establish persistent remote control on victim systems through the deployment of the AGEWHEEZE RAT.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
CERT-UA reported that the March 26-27 spoofing campaign was largely unsuccessful, with only a small number of infected personal devices identified belonging to employees of educational institutions. The disclosure clarified the campaign's real-world impact beyond the originally targeted sectors.
On 2026-03-28, the operators behind the CERT-UA spoofing campaign claimed responsibility through a linked Telegram channel. Following this, the activity was tracked under the designation UAC-0255, adding an attribution development to the incident.
Between March 26 and 27, 2026, a phishing campaign impersonating Ukraine's Computer Emergency Response Team targeted government entities, healthcare providers, financial providers, security firms, educational institutions, and software development companies in Ukraine. The operation was intended to deploy the AGEWHEEZE remote access trojan (RAT).
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecybersecuritynews.com
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourcescworld.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.