CERT-UA
-
Ukraine warns of campaign targeting clinics with malware that steals browser and WhatsApp data
Ukraine’s CERT-UA said a March to April 2026 campaign targeted clinics, hospitals and some government bodies with malware that could steal browser and WhatsApp data, using phishing emails, LNK files and HTA loaders.
-
CERT-UA impersonation phishing campaign spread AGEWHEEZE malware
A phishing campaign impersonating Ukraine’s CERT-UA spread AGEWHEEZE malware to organizations and individuals in March, though officials said only a small number of personal devices were infected.
-
CERT-UA advisory outlines PLUGGYAPE campaign using Signal and WhatsApp against Ukrainian forces
A CERT-UA advisory says PLUGGYAPE was used in October to December 2025 attacks on Ukrainian defense forces. Delivery used Signal and WhatsApp links to passworded archives that installed a PyInstaller executable and a Python backdoor.



