logo

CERT-UA reports PLUGGYAPE cyberattacks on defense forces

ID: 0f5db20f-807f-5d54-899e-95a8b235ddec

STIX ID: report--0f5db20f-807f-5d54-899e-95a8b235ddec

Feed Name: Security Affairs

Threat Score
82/100

Date Published: 2026-01-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

CERT-UA reported targeted PLUGGYAPE backdoor campaigns against Ukraine’s defense forces, attributed with medium confidence to the Russia-linked Void Blizzard (Laundry Bear). Attackers used social engineering over instant messaging to trick victims into running PyInstaller-packaged Python executables (often inside password-protected archives or with misleading extensions) that install a Python-based backdoor which communicates via WebSockets or MQTT, executes server-sent code, collects system identifiers, persists via the Run registry, employs anti-analysis checks (VM detection), and hides C2 details on public paste sites; the report also references a related 2024 Dutch police data breach linked to the same actor.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.