Kremlin-linked hackers pose as charities to spy on Ukraine’s military
ID: d09162ed-2d04-55e2-8f66-591736a4f148
STIX ID: report--d09162ed-2d04-55e2-8f66-591736a4f148
Feed Name: The Record from Recorded Future News
CERT-UA reported that Kremlin-linked APT Void Blizzard (also tracked as Laundry Bear / UAC-0190) ran a targeted cyber-espionage campaign from October–December 2025 against Ukrainian military personnel, using a new backdoor called PluggyApe. Attackers posed as charitable organizations and used messaging apps (Signal, WhatsApp) and password‑protected archives to deliver malicious executables, then upgraded the malware to add persistence and anti-analysis features while leveraging legitimate accounts and localized, highly tailored lures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
