Ukraine’s national Computer Emergency Response Team, CERT-UA, recorded 3,137 cyber incidents in the first half of 2026, as attackers increasingly relied on artificial intelligence, legitimate online services and mobile devices to conduct their operations.
The findings are included in CERT-UA’s latest analytical report, “Cyber Threats: Ukraine,” which examines incidents recorded during the first six months of the year and changes in the methods used by hostile groups.
The number of incidents increased by 8% compared with the previous six months. However, CERT-UA recorded only one critical incident, while the number of highly complex attacks declined by 20%.
Local authorities were the most frequently targeted, accounting for 37% of incidents. Government organisations represented another 22%, followed by the security and defence sector at 9% and energy at 8%.
AI makes cyber campaigns faster and easier to scale
One of the clearest developments identified by CERT-UA is the growing role of artificial intelligence throughout the attack process.
Previously, AI was mainly associated with writing phishing emails or assisting with individual pieces of malicious code. During the first half of 2026, analysts found indications of its use much more broadly — in email content, fake websites, scripts, loaders and individual malware functions.
This allows attackers to adapt the same campaign rapidly for different organisations, professions, regions or current events. Code and delivery methods can also be modified much faster than before.
CERT-UA notes that the resulting malware does not necessarily have to be technically advanced. Even relatively basic code may be sufficient for a single infection or the theft of information.
At the same time, characteristics such as polished text, code comments or particular file structures cannot by themselves prove that AI was involved. Such signs need to be assessed alongside other technical evidence.
Trusted platforms become part of the attack
Another widespread tactic is the use of legitimate internet services to disguise malicious activity.
Attackers used file-hosting platforms and GitHub to distribute malicious files, Telegram to transfer stolen information, and services such as ngrok and Cloudflare to conceal network traffic. Legitimate remote-administration software was also used to gain access to compromised systems.
In other cases, attackers exploited vulnerabilities in legitimate websites. Resources vulnerable to cross-site scripting, or websites that had already been compromised, were used as hidden points for delivering malware.
This makes detection more difficult because malicious traffic can resemble normal online activity, while simply blocking widely used platforms is often impractical.
Malware and social engineering dominate
Malware distribution remained the largest category of cyber incidents, accounting for 33% of cases recorded during the first half of the year. Social engineering represented 23%, system infections 15% and system compromises 4.5%.
Together, the most common categories accounted for nearly 84% of all recorded incidents.
The figures indicate that malicious messages, manipulation of users and attempts to steal credentials continue to provide attackers with some of their most effective entry points.
CERT-UA also identified new clusters of cyber threats during the period, including a growing focus on smartphones and other mobile devices.
Smartphones become a growing target
Both Android and iOS devices are increasingly being treated as a separate attack surface.
Their importance for communications among military personnel, government employees and civilians makes smartphones attractive for espionage, credential theft, further penetration of information systems and financially motivated attacks.
CERT-UA highlighted DarkSword, an exploit kit targeting iOS devices. The attacks use compromised legitimate websites, including Ukrainian government and news resources, in so-called watering-hole operations.
When a targeted user visits one of these websites, the browser can receive a chain of exploits targeting vulnerabilities in Safari and the operating system kernel. A successful attack can potentially give adversaries access to credentials, messages, contacts and call history without requiring obvious action from the victim.
Android users, meanwhile, have been targeted through malicious applications distributed via specially created websites. Some of these imitate resources associated with the Armed Forces of Ukraine, while others claim to provide information about aerial threats.
Government institutions remain under pressure
Since the beginning of 2026, CERT-UA has tracked campaigns targeting local authorities, critical infrastructure and military units.
Some attacks began with emails instructing recipients to install supposed software updates or official modules. Messages were sometimes presented as coming from Ukrainian government institutions or even CERT-UA itself.
Malware was distributed through archive attachments containing executable files or through links to legitimate websites vulnerable to cross-site scripting. The actual malicious files could then be hosted on legitimate platforms such as GitHub, adding another layer of concealment.
Between March and May, CERT-UA identified three campaigns impersonating its own notifications, an update for the Verkhovna Rada’s secure document management system and the Brave1 Security Hub application.
All three campaigns used AGEWHEEZE malware. One fake website imitating a CERT-UA resource also displayed technical indications that AI may have been used in its creation.
The campaigns illustrate a broader shift towards quickly constructed but convincing scenarios. Instead of relying exclusively on sophisticated technical exploits, attackers increasingly try to persuade victims that malicious software is a legitimate tool they need to install themselves.
More conventional threats nevertheless remain widespread. CERT-UA continues to observe frequent mass malware campaigns using accounting and financial themes, sometimes several times a week.
Private notaries, administrative service centres, territorial recruitment centres and medical institutions have also been targeted in attempts to gain access to information systems and potentially enter false information into state registers.
Other campaigns sought remote access to devices belonging to government employees, while cyber espionage operations continued to target military innovation centres, military formations, law enforcement bodies and other organisations.
Overall, CERT-UA’s findings point to a cyber threat environment in which sophisticated intelligence operations increasingly coexist with inexpensive, rapidly produced campaigns. AI and legitimate online platforms are making attacks easier to adapt and disguise, while social engineering remains one of the simplest ways for adversaries to reach their targets.