Details of fresh cyberattacks using malware called PLUGGYAPE that targeted Ukraine’s defense forces between October and December 2025 have been released by the Computer Emergency Response Team of Ukraine (CERT-UA).
A Russian hacker group known as Void Blizzard (also known as Laundry Bear or UAC-0190) has been identified with medium confidence as the source of the activity. It is thought that the threat actor has been active since at least April 2024.
Threat actors pose as charitable organizations to trick targets into clicking on a seemingly innocuous link (“harthulp-ua[.]com” or “solidarity-help[.]org”) that impersonates the foundation and downloads a password-protected archive. Attack chains that distribute the malware use WhatsApp and Signal as vectors.
An executable made with PyInstaller that eventually resulted in the deployment of PLUGGYAPE may be found in the archives. According to CERT-UA, the backdoor’s subsequent revisions have included obfuscation read more about PLUGGYAPE Malware Uses Signal and WhatsApp to Target Ukrainian Defense Forces.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
