Ukrainian emergency services and hospitals have reportedly been targeted in a cyberespionage campaign involving a newly identified piece of malware known as AgingFly, according to information referenced from DataBreaches.net.
The campaign appears to focus on critical infrastructure sectors within Ukraine, specifically targeting emergency response organizations and healthcare facilities. These types of institutions handle highly sensitive operational and personal data, making them attractive targets for state-sponsored or advanced threat actors seeking intelligence advantages.
The malware identified in this campaign, AgingFly, is described as a new strain, suggesting that threat actors may have developed or deployed a custom toolset specifically for this operation. The use of novel malware is a common tactic among sophisticated adversaries seeking to evade detection by security tools that rely on known malware signatures.
Attacks against hospitals and emergency services carry significant implications beyond data theft. Such organizations are responsible for life-safety functions, and any disruption to their operations — whether through data exfiltration, system compromise, or service interruption — can have serious humanitarian consequences, particularly in an active conflict environment such as Ukraine.
As of the time of this reporting, detailed technical indicators of compromise, full attribution, and the complete scope of the campaign have not been independently verified through additional confirmed sources. IsacChain will continue to monitor this situation and provide updates as more verified information becomes available.
Organizations in the healthcare and emergency services sectors, particularly those operating in or connected to conflict zones, are advised to remain vigilant, review their endpoint detection capabilities, and ensure that threat intelligence feeds are updated to reflect emerging threats.
Source: DataBreaches.net — https://databreaches.net/2026/04/18/ukrainian-emergency-services-and-hospitals-hit-by-espionage-campaign-using-new-agingfly-malware/