Information Security 2 min read

Public sector threats drive shift to proactive cyber defense

UAC-0057 has updated its tools for public sector attacks. We analyze incident statistics and the benefits of shifting to a Zero Trust architecture.

The CERT-UA government team has warned of updated tools used by the UAC-0057 cyber group. Attackers are actively deploying new malware—OYSTERFRESH, OYSTERSHUCK, and OYSTERBLUES—in phishing campaigns targeting Ukrainian government agencies. This highlights the urgent need to revise security approaches in the public sector.

The overall threat level remains high. Throughout 2025, CERT-UA processed nearly 6,000 cyber incidents, a 37.4% increase compared to 2024 (4,315 incidents). Although no critical cases were recorded in the second half of 2025, the growing volume of attacks indicates continuous pressure on government information systems.

Why compliance is no longer enough

Many organizations view compliance with standards (such as ISO/IEC 27001 or KSZI requirements) as the ultimate goal. However, this is only a baseline. Modern phishing attacks leverage sophisticated social engineering and technical tools to bypass filters, meaning standard antivirus solutions and basic staff training no longer guarantee security.

What this means for the market

The continuous pressure on government information systems and the deployment of sophisticated malware mean that public sector organizations and their IT partners face elevated operational and reputational risks. A single successful phishing compromise can lead to data leaks, disruption of critical state services, and a broader loss of public trust in digital government infrastructure.

Next steps

To achieve true resilience, government agencies must integrate cyber defense into their operational processes through a Zero Trust architecture. This approach involves:

  • Network microsegmentation: dividing infrastructure into isolated segments to limit lateral movement by attackers.
  • Multi-factor authentication (MFA): mandatory verification for all users and devices.
  • Continuous monitoring: using SIEM systems to analyze behavior and quickly detect anomalies.
  • Automated response: instant blocking of suspicious activity and threat isolation.

Proactive defense also requires regular penetration testing (pentests), phishing simulations, supply chain security controls, and clear incident response procedures within defined timeframes (24/72 hours).

Prepared by a Software Ukraine member. Original publication.

Sources & materials

Materials and sources used in this article.

  1. Original publication — intecracy.com