← Back to BrewedIntel
malwarehighData Theft MalwareTargeted CampaignUAC-0247

Apr 16, 2026 • [email protected] (The Hacker News)

UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign

CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including...

Source
The Hacker News
Category
malware
Severity
high

Executive Summary

CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including clinics and emergency hospitals. The campaign, observed between March and April, delivers malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. This data-theft operation focuses on exfiltrating credentials, personal information, and communications from critical infrastructure entities. Organizations should ensure browsers and messaging applications are updated, implement strong access controls, monitor for suspicious data exfiltration activities, and deploy endpoint detection solutions to identify credential-stealing malware.

Summary

The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April

Published Analysis

CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including clinics and emergency hospitals. The campaign, observed between March and April, delivers malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. This data-theft operation focuses on exfiltrating credentials, personal information, and communications from critical infrastructure entities. Organizations should ensure browsers and messaging applications are updated, implement strong access controls, monitor for suspicious data exfiltration activities, and deploy endpoint detection solutions to identify credential-stealing malware. The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April

Linked Entities

  • UAC-0247