logo

Russia targets Ukrainian conscripts with Windows, Android malware

ID: 745b412d-f240-58d6-a309-de98ad4540bd

STIX ID: report--745b412d-f240-58d6-a309-de98ad4540bd

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

UNC5812 ran a hybrid espionage and influence operation posing as a Ukraine-friendly "Civil Defense" persona via a Telegram channel and website to push a fake "Sunspinner" app that installs Windows malware (Pronsis Loader -> PureStealer) and an Android backdoor (CraxsRAT), enabling credential theft, real-time location tracking, audio recording and broader data exfiltration; Google has added protections (Play and Safe Browsing) and published associated IOCs on VirusTotal.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.