Tuesday, September 8, 2026

Fake CERT-UA Site Spreads Go-Based RAT in Phishing Campaign

Hackers have launched a targeted phishing campaign by cloning Ukraine’s official CERT-UA website and distributing malicious software disguised as a security tool, according to a new alert from the national cyber response team.

Targets included government agencies, financial institutions, educational bodies, medical centers, and IT companies.

The emails urged recipients to download a password-protected archive labeled “CERT_UA_protection_tool.zip” or “protection_tool.zip” from the Files FM file-sharing service.

The messages claimed the archive contained a “specialized protection tool,” but in reality, it delivered a remote access trojan (RAT) known as AGEWHEEZE.

The activity was observed between March 26 and 27, 2026, when threat actors sent emails impersonating CERT-UA to a wide range of organizations.

Researchers also identified a fraudulent website, cert-ua[.]tech, designed to mimic the official CERT-UA portal. The site reused legitimate content from cert.gov.ua and provided instructions to download the same malicious tool, increasing the credibility of the attack.

Go-Based RAT Capabilities

The payload inside the archive installs AGEWHEEZE, a multifunctional RAT written in the Go programming language. Once executed, the malware provides attackers with extensive control over infected systems.

Its capabilities include:

  • Executing commands and managing files.
  • Capturing screenshots and monitoring user activity.
  • Simulating mouse and keyboard input.
  • Accessing clipboard data.
  • Managing processes and system services.

The malware ensures persistence by installing itself in directories such as %APPDATA%\SysSvc\SysSvc.exe or %APPDATA%\service\service.exe.

Using the Files.fm service to host archives(Source :CERT-UA ).
Using the Files.fm service to host archives(Source :CERT-UA ).

It also creates scheduled tasks like “SvcHelper” and “CoreService” to maintain elevated privileges.

Communication with its command-and-control (C2) server occurs via WebSockets, specifically through 54[.]36.237.92:8443, hosted on OVH infrastructure.

Investigators discovered a control panel labeled “The Cult” running on the same server, protected by an authentication page.

CERT-UA linked the campaign to a threat actor identified as UAC-0255. Attribution was strengthened after a Telegram channel named “Cyber Serp” publicly claimed responsibility for the attack on March 28, 2026.

Example of a fake website hXXps://cert-ua[.]tech/ (Source :CERT-UA ).
Example of a fake website hXXps://cert-ua[.]tech/ (Source :CERT-UA ).

Analysis of the fake website’s HTML code revealed embedded references to the group, including the message: “With Love, CYBER SERP.”

The domain cert-ua[.]tech was registered on March 27, 2026, and briefly used with a valid GlobalSign SSL certificate before going offline.

Additional infrastructure tied to the campaign includes domains such as creepy[.]ltd and hiddify.creepy[.]ltd, as well as malicious download links hosted on Files.fm.

Limited Impact but Growing Concern

CERT-UA reported that the campaign had limited success, with only a small number of infections detected. These primarily affected personal devices belonging to employees of educational institutions. The agency provided immediate assistance to contain the incidents.

Example of a web panel hosted on a management server (Source :CERT-UA ).
 Example of a web panel hosted on a management server (Source :CERT-UA ).

Despite the low infection rate, the campaign highlights the increasing sophistication of phishing attacks, particularly those enhanced by artificial intelligence.

The use of cloned websites, realistic email lures, and AI-generated content makes detection more difficult for users.

CERT-UA urges organizations to strengthen their defenses by reducing their attack surface and enforcing stricter system policies. Recommended measures include:

  • Configuring built-in protections such as Software Restriction Policies (SRP) and AppLocker.
  • Verifying the authenticity of emails and download sources.
  • Blocking suspicious domains and monitoring outbound connections.
  • Using endpoint protection tools capable of detecting RAT behavior.

The agency also emphasized the importance of collaboration with telecom providers, which helped distribute threat intelligence and support national cyber defense efforts.

This campaign serves as a reminder that even trusted institutions can be impersonated, and vigilance remains critical in defending against evolving cyber threats.

Follow us on Google NewsLinkedIn, and X to Get Instant Updates and Set GBH as a Preferred Source in Google.

Mayura Kathir
Mayura Kathirhttps://gbhackers.com/
Mayura Kathir is a cybersecurity reporter at GBHackers News, covering daily incidents including data breaches, malware attacks, cybercrime, vulnerabilities, zero-day exploits, and more.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Mathspace Data Breach Exposes Personal Data of Over 1 Million Students, Parents and Staff

Mathspace, an online mathematics learning platform used by schools...

New InjectEave Attack Lets Hackers Eavesdrop on Headphone Audio From 30 Meters Away

Security researchers have unveiled InjectEave, an electromagnetic side-channel attack...

PoisonedRefresh Malware Backdoors F5 BIG-IP Servers With Memory-Only PHP Web Shells

A sophisticated Linux implant linked to compromised F5 BIG-IP...

Natural Resources Wales Data Breach Exposes Sensitive Employee Diversity Data

Natural Resources Wales (NRW) has reported a personal data...

ConnectWise ScreenConnect Remote Access Flaw Impacts Guest File Transfer Sessions

ConnectWise has announced a security issue affecting file transfer...

Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

A large-scale phishing operation is abusing trusted Google services...

OpenAI Commits $1 Billion in Daybreak AI Cyber Tools to Protect Critical Infrastructure

OpenAI has announced a $1 billion global commitment to...

Tengu Mirai-Style Linux Bot Hides as Kernel Worker to Launch DDoS and Proxy Attacks

A newly analyzed Linux malware sample, dubbed Tengu, combines...

Related Articles

Recent News