Russia targets Ukrainian conscripts with Windows, Android malware
ID: 745b412d-f240-58d6-a309-de98ad4540bd
STIX ID: report--745b412d-f240-58d6-a309-de98ad4540bd
Feed Name: Bleeping Computer
Threat Score
UNC5812 ran a hybrid espionage and influence operation posing as a Ukraine-friendly "Civil Defense" persona via a Telegram channel and website to push a fake "Sunspinner" app that installs Windows malware (Pronsis Loader -> PureStealer) and an Android backdoor (CraxsRAT), enabling credential theft, real-time location tracking, audio recording and broader data exfiltration; Google has added protections (Play and Safe Browsing) and published associated IOCs on VirusTotal.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
