logo

Hybrid Russian Espionage and Influence Campaign Aims to Compromise Ukrainian Military Recruits and Deliver Anti-Mobilization Narratives

ID: 917e824e-42bc-53a2-a607-eaf7eb8bcaa8

STIX ID: report--917e824e-42bc-53a2-a607-eaf7eb8bcaa8

Feed Name: Google Cloud Threat Intelligence

Threat Score
70/100

Date Published: 2024-10-28

Date Updated: 2026-04-27

Author: Google Threat Intelligence Group

...
...

The Civil Defense website distributed multi-stage malware for Windows and Android: a custom Pronsis Loader (CivilDefense.exe) that chains to a PHP/JVM-compiled downloader and ultimately deploys the PURESTEALER .NET infostealer (MD5s provided), and an Android APK variant that delivers the CRAXSRAT backdoor; the report includes MD5 hashes and a download URL as IOCs and describes the delivery and capabilities of both payloads.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.