logo

Kremlin-linked hackers pose as charities to spy on Ukraine’s military

ID: d09162ed-2d04-55e2-8f66-591736a4f148

STIX ID: report--d09162ed-2d04-55e2-8f66-591736a4f148

Feed Name: The Record from Recorded Future News

Threat Score
88/100

Date Published: 2026-01-13

Date Updated: 2026-05-01

...
...

CERT-UA reported that Kremlin-linked APT Void Blizzard (also tracked as Laundry Bear / UAC-0190) ran a targeted cyber-espionage campaign from October–December 2025 against Ukrainian military personnel, using a new backdoor called PluggyApe. Attackers posed as charitable organizations and used messaging apps (Signal, WhatsApp) and password‑protected archives to deliver malicious executables, then upgraded the malware to add persistence and anti-analysis features while leveraging legitimate accounts and localized, highly tailored lures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.