SYMBOLCOMMON_NAMEaka. SYNONYMS
win.agingfly (Back to overview)

AGINGFLY


According to CERT-UA, AGINGFLY is a C#-based remote-control tool that can execute commands, download files, capture screenshots, and run a keylogger, effectively enabling full remote control of an infected host. Its C2 communication uses WebSockets with AES-CBC encryption, and unlike typical implants, command handlers are not embedded in the binary; they are delivered from the C2 as source code and compiled at runtime. The malware also appears in a multi-stage loader chain, with a stager that establishes a remote connection and covert execution, and it can leverage process injection to hide in legitimate system processes.

References
2026-04-15Cert-UACert-UA
Hospitals, local governments, and FPV operators are in the focus of the UAC-0247 (UAC-0244) cyber threat cluster
SILENTLOOP AGINGFLY Chisel Havoc xmrig

There is no Yara-Signature yet.