Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
CERT-UA

CERT-UA Vendor Cyber Rating & Cyber Score

cert.gov.ua

CERT-UA - governmental Computer Emergencies Response Team of Ukraine operates within the State Service for Special Communications and Information Protection of Ukraine. Since 2009 been an accredited member of the global Forum of Incident Response and Security Teams (https://lnkd.in/eDZKZiyH). Let us know about a cyber incident that affects the Ukrainian network segment: https://lnkd.in/ePXthb9X.


CERT-UA A.I CyberSecurity Scoring

CERT-UA
Company Information
Website:https://cert.gov.ua
Employees number:23
Number of followers:1,836
NAICS:541514
Industry Type:Computer and Network Security
Homepage:cert.gov.ua
CERT-UA Risk Score (AI oriented)
Between 650 and 699
logo
CERT-UAComputer and Network Security
Updated:
01/04/2026
669/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
CERT-UA Global Score (TPRM)
xxxx
logo
CERT-UAComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

CERT-UA
CERT-UAWeak
Current Score
669B (WEAK)
01000
4 incidents
-21 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
674Before Incident
MAY 2026
672Before Incident
APRIL 2026
669Before Incident
MARCH 2026
689Before Incident
Cyber Attack
26 Mar 2026CERT-UA
CERT-UA: CERT-UA Impersonation Campaign Spread AGEWHEEZE Malware to 1 Million Emails

Ukrainian CERT-UA Targeted in Phishing Campaign Distributing AGEWHEEZE Malware

668After Incident
LOW-21
CER1775061546
Ukrainian CERT-UA Targeted in Phishing Campaign Distributing AGEWHEEZE Malware The Computer Emergency Response Team of Ukraine (CERT-UA) has uncovered a sophisticated phishing campaign in which threat actors impersonated the agency to distribute the AGEWHEEZE remote administration trojan. The attacks, attributed to the group UAC-0255, occurred on March 26–27, 2026, targeting state organizations, medical centers, security firms, educational institutions, financial entities, and software developers. Emails were sent from the spoofed address incidents@cert-ua[.]tech, urging recipients to download a password-protected ZIP file ("CERT_UA_protection_tool.zip") hosted on Files.fm. The archive contained malware disguised as legitimate security software, later identified as AGEWHEEZE, a Go-based remote access trojan (RAT). AGEWHEEZE establishes communication with a command-and-control server (54.36.237[.]92) via WebSockets and supports extensive malicious functionality, including command execution, file manipulation, clipboard hijacking, input emulation, screenshot capture, and process management. It ensures persistence through scheduled tasks, Windows Registry modifications, or Startup directory entries. CERT-UA reported the campaign had limited success, with only a few infections detected primarily on personal devices of educational institution employees. The agency provided remediation support to affected parties. Investigations revealed the fraudulent domain cert-ua[.]tech was likely generated using AI tools, with its HTML source code containing a Russian-language comment: "С Любовью, КИБЕР СЕРП" ("With Love, CYBER SERP"). The threat actor, operating under the alias Cyber Serp, claims to be a Ukrainian "cyber-underground" collective with over 700 Telegram subscribers (channel created in November 2025). In Telegram posts, Cyber Serp asserted the phishing campaign targeted 1 million ukr[.]net mailboxes, claiming over 200,000 devices were compromised. The group also took responsibility for a February 2026 breach of Ukrainian cybersecurity firm Cipher, alleging access to server dumps, client databases, and source code for its CIPS products. Cipher confirmed the incident but stated the compromised employee had access only to a non-sensitive project, with no impact on its infrastructure.
INCIDENT DETAILS -
TYPE
Phishing Campaign
MOTIVATION
Cyber Espionage, Data Exfiltration
IMPACT
Data Compromised: Potential access to sensitive data (e.g., client databases, source code)Systems Affected: Personal devices of employees (primarily educational institutions)Operational Impact: Limited success; remediation support providedBrand Reputation Impact: Potential reputational damage to CERT-UA and targeted entitiesIdentity Theft Risk: High (due to RAT capabilities)
DATA BREACH
Client databasesSource codePotentially sensitive project dataSensitivity Of Data: High (PII, proprietary code)Data Exfiltration: Alleged (claimed by threat actor)Personally Identifiable Information: Potential (due to RAT capabilities)
FEBRUARY 2026
688Before Incident
JANUARY 2026
687Before Incident
DECEMBER 2025
686Before Incident
NOVEMBER 2025
684Before Incident
OCTOBER 2025
683Before Incident
SEPTEMBER 2025
681Before Incident
AUGUST 2025
680Before Incident
JULY 2025
678Before Incident
MARCH 2025
736Before Incident
Breach
01 Mar 2025CERT-UA
CERT-UA

WRECKSTEEL Malware Attacks on Ukrainian Government Agencies and Critical Infrastructure

670After Incident
CRITICAL-66
CER000040525
In March 2025, CERT-UA, Ukraine's state computer emergency response team, detected three targeted cyberattacks utilizing WRECKSTEEL malware to exfiltrate sensitive data from government agencies and critical infrastructure. The attacks involved sending spear-phishing emails with malicious links to install VBScript and PowerShell-based versions of the WRECKSTEEL stealer, which searched for and extracted a variety of sensitive file types and took screenshots for reconnaissance and further exploitation. The lack of persistence mechanisms in these tools necessitates immediate reporting of cyber intrusion signs to CERT-UA to initiate protective actions. These incidents underscore the persistent threat landscape facing Ukrainian digital infrastructure in a geopolitically tense environment.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Data Exfiltration
IMPACT
Data Compromised: Variety of sensitive file typesSystems Affected: Government agencies and critical infrastructure
DATA BREACH
Type Of Data Compromised: Sensitive file types and screenshotsSensitivity Of Data: HighData Exfiltration: YesFile Types Exposed: Variety of sensitive file types
JULY 2024
749Before Incident
Cyber Attack
01 Jul 2024CERT-UA
Ukrainian Government’s Computer Emergency Response Team (CERT-UA)

GhostWriter APT Group Targets Ukrainian Government with PicassoLoader Malware

732After Incident
CRITICAL-17
CER006080624
The Belarus-linked APT group GhostWriter targeted Ukrainian governmental organizations with PicassoLoader malware, distributing documents with malicious macros. These documents, which pertained to taxation and financial-economic metrics, were aimed at project office specialists and local government employees. This strategy suggests an intention for cyber espionage against the Ukrainian government. Mandiant linked GhostWriter to Belarus, known for disinformation and news website CMS compromises. The campaign impacted both Ukraine's internal governance and could potentially affect Eastern European regional stability.
INCIDENT DETAILS -
TYPE
Cyber Espionage
MOTIVATION
Cyber Espionage
IMPACT
Internal GovernanceRegional Stability
JUNE 2016
749Before Incident
Vulnerability
16 Jun 2016CERT-UA
Microsoft: Microsoft Office Zero-day Vulnerability Actively Exploited in Attacks

Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509)

748After Incident
CRITICAL-1
MIC1769489765
Microsoft Patches Actively Exploited Zero-Day in Office (CVE-2026-21509) On January 26, 2026, Microsoft released emergency out-of-band security updates to address CVE-2026-21509, a zero-day vulnerability in Microsoft Office that attackers are actively exploiting. The flaw, rated "Important" with a CVSS score of 7.8, allows threat actors to bypass OLE mitigations by leveraging untrusted inputs in security decisions. The vulnerability enables local attackers to circumvent Office protections after tricking users into opening malicious files typically via phishing or social engineering. Exploitation requires low complexity, no privileges, and user interaction, but results in high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). The Microsoft Threat Intelligence Center (MSTIC) confirmed active exploitation, marking it as the second zero-day patched this month following January’s Patch Tuesday updates. ### Affected Products & Mitigation The flaw impacts legacy and current Office editions, including: - Office 2016 (32/64-bit) – KB5002713 (Build 16.0.5539.1001) - Office LTSC 2024/2021 – Automatic service-side protection post-restart - Microsoft 365 Apps (Enterprise) – Automatic updates - Office 2019 – Build 16.0.10417.20095 Office 2016/2019 users must apply updates or manually adjust the registry by adding a DWORD "Compatibility Flags" (value 400) under: `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\16.0\Common\COM Compatibility\{EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}` (Paths may vary for Click-to-Run deployments; registry backups are recommended.) ### Threat Landscape & Recommendations While no public proof-of-concept (PoC) or attributed threat actors have been disclosed, organizations are advised to prioritize patching, enable auto-updates, and monitor for phishing indicators of compromise (IOCs) particularly suspicious Office attachments. Attackers frequently exploit such vulnerabilities for ransomware or APT initial access, making EDR monitoring for COM/OLE anomalies critical. The CISA Known Exploited Vulnerabilities (KEV) catalog may list this flaw in the near future.
INCIDENT DETAILS -
TYPE
Zero-Day Vulnerability
IMPACT
Systems Affected: Microsoft Office (legacy and current editions)Operational Impact: High impact on confidentiality, integrity, and availability (C:H/I:H/A:H)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for CERT-UA ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in May 2026 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in April 2026 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in March 2026 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in February 2026 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in January 2026 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in December 2025 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in November 2025 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in October 2025 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in September 2025 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in August 2025 ?
?
What was CERT-UA's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on CERT-UA's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with CERT-UA ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view CERT-UA's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?