Ukraine's army targeted in new charity-themed malware campaign
ID: 73e989b1-f02e-5ee3-86bb-bc311aaea20b
STIX ID: report--73e989b1-f02e-5ee3-86bb-bc311aaea20b
Feed Name: Bleeping Computer
CERT-UA reports a charity-themed social-engineering campaign (Oct–Dec 2025) targeting Ukrainian Defense Forces that distributes the PluggyApe backdoor via Signal/WhatsApp messages and fake charity websites; the actors used PyInstaller-built PIF loaders, registry persistence, MQTT-based comms, and dynamic base64-encoded C2s hosted on services like rentry.co and pastebin.com, with medium-confidence attribution to the Russia-affiliated Void Blizzard / Laundry Bear and IoCs published by CERT-UA.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
