Threat Actors Targeting Ukraine’s Defense Forces with Charity-Themed Malware Campaign
ID: 8c166a2c-8414-5900-b32a-a872721b16bf
STIX ID: report--8c166a2c-8414-5900-b32a-a872721b16bf
Feed Name: cybersecurityNews.com
Executive summary: Between October and December 2025 a threat actor tracked as UAC-0190 (aka Void Blizzard) ran a targeted social-engineering campaign leveraging fake charity websites to deliver a Python backdoor called PLUGGYAPE to Ukrainian Defense Forces; PLUGGYAPE implements device fingerprinting, Windows Run persistence, WebSocket/MQTT JSON command-and-control, and evolved into a more obfuscated PLUGGYAPE.V2 that uses public paste services for hidden infrastructure and VM-detection checks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
