From clinics to government: UAC-0247 expands cyber campaign across Ukraine

2026-04-16T14:51:48Z2ba38d1c1f2b22b12dacbc6f35e11112351002b34a721e8035bdc8854c06e195
Android RATBasic-FitCERT-UACISAKnown Exploited VulnerabilitiesMeta adsMiraxOperation AtlanticPHP ComposerPerforce VCSRockstar GamesSharePointShinyHuntersUAC-0247actively exploitedcryptocurrency theftdata breachenergy infrastructureheating plantnginx-uipro-Russian groupremote code executionzero-day

What happened

Multiple high-impact cyber incidents and vulnerabilities reported: CERT-UA attributes a campaign by UAC-0247 targeting Ukrainian government bodies and municipal healthcare facilities to steal browser and WhatsApp data. Sweden says a pro‑Russian-linked group attempted a cyberattack on a heating plant, underscoring threats to energy infrastructure. A critical, actively exploited nginx-ui authentication bypass (CVE-2026-33032, CVSS 9.8) allows full server takeover, while Microsoft fixed an actively exploited SharePoint zero-day (CVE-2026-32201) in April Patch Tuesday. Other items include Mirax, a

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
2ba38d1c1f2b22b12dacbc6f35e11112351002b34a721e8035bdc8854c06e195
Enrichment time
2026-04-16T14:51:48Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.