Apr 16, 2026 • [email protected] (The Hacker News)
UAC-0247 Targets Ukrainian Clinics and Government in Data-Theft Malware Campaign
CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including...
Executive Summary
CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including clinics and emergency hospitals. The campaign, observed between March and April, delivers malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. This data-theft operation focuses on exfiltrating credentials, personal information, and communications from critical infrastructure entities. Organizations should ensure browsers and messaging applications are updated, implement strong access controls, monitor for suspicious data exfiltration activities, and deploy endpoint detection solutions to identify credential-stealing malware.
Summary
The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April
Published Analysis
CERT-UA has disclosed a new campaign by threat actor UAC-0247 targeting government agencies and municipal healthcare institutions in Ukraine, including clinics and emergency hospitals. The campaign, observed between March and April, delivers malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. This data-theft operation focuses on exfiltrating credentials, personal information, and communications from critical infrastructure entities. Organizations should ensure browsers and messaging applications are updated, implement strong access controls, monitor for suspicious data exfiltration activities, and deploy endpoint detection solutions to identify credential-stealing malware. The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April The Computer Emergencies Response Team of Ukraine (CERT-UA) has disclosed details of a new campaign that has targeted governments and municipal healthcare institutions, mainly clinics and emergency hospitals, to deliver malware capable of stealing sensitive data from Chromium-based web browsers and WhatsApp. The activity, which was observed between March and April
Linked Entities
- UAC-0247