logo

Ukraine's army targeted in new charity-themed malware campaign

ID: 73e989b1-f02e-5ee3-86bb-bc311aaea20b

STIX ID: report--73e989b1-f02e-5ee3-86bb-bc311aaea20b

Feed Name: Bleeping Computer

Threat Score
86/100

Date Published: 2026-01-13

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

CERT-UA reports a charity-themed social-engineering campaign (Oct–Dec 2025) targeting Ukrainian Defense Forces that distributes the PluggyApe backdoor via Signal/WhatsApp messages and fake charity websites; the actors used PyInstaller-built PIF loaders, registry persistence, MQTT-based comms, and dynamic base64-encoded C2s hosted on services like rentry.co and pastebin.com, with medium-confidence attribution to the Russia-affiliated Void Blizzard / Laundry Bear and IoCs published by CERT-UA.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.