Hackers targeting Ukrainian orgs with MerlinAgent info stealer

Hackers targeting Ukrainian orgs with MerlinAgent info stealer

The Computer Emergency Response Team of Ukraine (CERT-UA) is warning about a new information-stealing campaign targeting Ukraine’s government entities with the MerlinAgent malware.

The attacks were first spotted in July 2023, according to a security alert.

The new campaign involves malicious messages purportedly sent from CERT-UA that contain an attachment in the form of a CHM file named “Внутрішні кіберзагрози” (Internal Cyber Threats).

Upon opening, the file will trigger the execution of a JavaScript code and a PowerShell script meant to download and unzip a GZIP archive named “ctlhost.exe.tmp” containing an executable file (ctlhost.exe). When executed, this file will download the MerlinAgent malware onto the compromised system.

CERT-UA is tracking this malicious activity as UAC-0154.


Back to the list

Latest Posts

JSCEAL malware campaign targets crypto app users

JSCEAL malware campaign targets crypto app users

The JSCEAL campaign leverages malvertising primarily on social media platforms.
30 July 2025
Chinese firms linked to Salt Typhoon behind dozens of tech patents for cyber espionage tools

Chinese firms linked to Salt Typhoon behind dozens of tech patents for cyber espionage tools

The patents mention tools for encrypted endpoint data collection, forensic access to Apple devices, and remote control of routers and smart home systems.
30 July 2025
Scattered Spider targets data storage systems via IT help desk impersonation

Scattered Spider targets data storage systems via IT help desk impersonation

The joint advisory was updated with the latest data from FBI-led investigations as recent as June 2025.
30 July 2025