From clinics to government: UAC-0247 expands cyber campaign across Ukraine
2026-04-16T14:51:48Z•2ba38d1c1f2b22b12dacbc6f35e11112351002b34a721e8035bdc8854c06e195
Android RATBasic-FitCERT-UACISAKnown Exploited VulnerabilitiesMeta adsMiraxOperation AtlanticPHP ComposerPerforce VCSRockstar GamesSharePointShinyHuntersUAC-0247actively exploitedcryptocurrency theftdata breachenergy infrastructureheating plantnginx-uipro-Russian groupremote code executionzero-day
What happened
Multiple high-impact cyber incidents and vulnerabilities reported: CERT-UA attributes a campaign by UAC-0247 targeting Ukrainian government bodies and municipal healthcare facilities to steal browser and WhatsApp data. Sweden says a pro‑Russian-linked group attempted a cyberattack on a heating plant, underscoring threats to energy infrastructure. A critical, actively exploited nginx-ui authentication bypass (CVE-2026-33032, CVSS 9.8) allows full server takeover, while Microsoft fixed an actively exploited SharePoint zero-day (CVE-2026-32201) in April Patch Tuesday. Other items include Mirax, a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 2ba38d1c1f2b22b12dacbc6f35e11112351002b34a721e8035bdc8854c06e195
- Enrichment time
- 2026-04-16T14:51:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.