Hackers targeting Ukrainian orgs with MerlinAgent info stealer

Hackers targeting Ukrainian orgs with MerlinAgent info stealer

The Computer Emergency Response Team of Ukraine (CERT-UA) is warning about a new information-stealing campaign targeting Ukraine’s government entities with the MerlinAgent malware.

The attacks were first spotted in July 2023, according to a security alert.

The new campaign involves malicious messages purportedly sent from CERT-UA that contain an attachment in the form of a CHM file named “Внутрішні кіберзагрози” (Internal Cyber Threats).

Upon opening, the file will trigger the execution of a JavaScript code and a PowerShell script meant to download and unzip a GZIP archive named “ctlhost.exe.tmp” containing an executable file (ctlhost.exe). When executed, this file will download the MerlinAgent malware onto the compromised system.

CERT-UA is tracking this malicious activity as UAC-0154.


Back to the list

Latest Posts

UMMC pharmacist installed malware on hundreds hospital computers to spy on doctors

UMMC pharmacist installed malware on hundreds hospital computers to spy on doctors

His alleged actions included watching the women undress, breastfeed, and engage in private activities such as intimate acts with their husbands.
8 April 2025
Dark web leak site of Everest ransomware gang hacked and defaced

Dark web leak site of Everest ransomware gang hacked and defaced

Experts speculate that the Everest gang’s use of a WordPress template for their leak site might have played a key role in the breach.
8 April 2025
Threat actors exploiting recent CrushFTP auth bypass flaw for persistent access

Threat actors exploiting recent CrushFTP auth bypass flaw for persistent access

The vulnerability, now tracked as CVE-2025-31161, allows attackers to bypass authentication and gain unauthorized access to targeted systems.
8 April 2025