CERT-UA reports PLUGGYAPE cyberattacks on defense forces
ID: 0f5db20f-807f-5d54-899e-95a8b235ddec
STIX ID: report--0f5db20f-807f-5d54-899e-95a8b235ddec
Feed Name: Security Affairs
CERT-UA reported targeted PLUGGYAPE backdoor campaigns against Ukraine’s defense forces, attributed with medium confidence to the Russia-linked Void Blizzard (Laundry Bear). Attackers used social engineering over instant messaging to trick victims into running PyInstaller-packaged Python executables (often inside password-protected archives or with misleading extensions) that install a Python-based backdoor which communicates via WebSockets or MQTT, executes server-sent code, collects system identifiers, persists via the Run registry, employs anti-analysis checks (VM detection), and hides C2 details on public paste sites; the report also references a related 2024 Dutch police data breach linked to the same actor.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
