PLUGGYAPE Malware Targets Ukrainian Defense Forces via Signal and WhatsApp
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Ukrainian Computer Emergency Response Team (CERT-UA) disclosed details of cyber attacks involving PLUGGYAPE malware targeting its defense forces from October to December 2025. This malware is linked to the Russian hacking group Void Blizzard, also known as Laundry Bear or UAC-0190, which has been active since at least April 2024. Attackers used instant messaging platforms Signal and WhatsApp, impersonating charity organizations to lure victims into clicking on malicious links.
Upon clicking, users downloaded a password-protected archive containing an executable created with PyInstaller, leading to the deployment of PLUGGYAPE. CERT-UA noted that the malware has evolved to include obfuscation and anti-analysis measures, making it harder to detect in virtual environments. The malware establishes communication with a remote server using WebSocket or Message Queuing Telemetry Transport (MQTT), enabling attackers to execute arbitrary code on compromised hosts.
In December 2025, support for MQTT communication was added, enhancing the malware’s capabilities. The command-and-control (C2) addresses are retrieved from external paste services like rentry.co and pastebin.com, stored in base64-encoded form, which helps maintain operational security for the attackers. This method allows them to update C2 servers in real-time if their original infrastructure is compromised.
CERT-UA highlighted that initial interactions with targets increasingly use legitimate accounts and phone numbers of Ukrainian mobile operators, often in the Ukrainian language. Attackers may demonstrate detailed knowledge about their targets, making these attacks particularly deceptive.
In addition to PLUGGYAPE, CERT-UA reported other threats targeting Ukrainian defense forces and local governments. For instance, a threat cluster known as UAC-0239 sent phishing emails from UKR.net and Gmail addresses, leading to a Go-based stealer named FILEMESS that exfiltrates files to Telegram. Another group, UAC-0241, executed spear-phishing campaigns using ZIP archives containing Windows shortcut files that trigger malicious scripts.
Implications for Cybersecurity
The use of widely available messaging platforms for malware distribution highlights a growing trend in cyber threats. Users and organizations should be vigilant about unsolicited messages, especially those claiming to be from charitable organizations. The sophistication of these attacks, including the use of legitimate accounts and targeted knowledge, underscores the need for enhanced security measures.
Organizations should implement strict verification processes for communications, especially those involving sensitive information or links. Regular training on recognizing phishing attempts and suspicious communications can help mitigate risks. Additionally, monitoring for unusual activities on devices and networks is crucial to detect potential breaches early.
Key Takeaways
- Be cautious of unsolicited messages on messaging platforms like Signal and WhatsApp, especially those from unknown contacts.
- Verify the legitimacy of any links claiming to be from charitable organizations before clicking.
- Implement multi-factor authentication (MFA) on accounts to enhance security against unauthorized access.
- Regularly train staff on recognizing phishing attempts and suspicious communications.
- Monitor network and device activity for any signs of unauthorized access or unusual behavior.
Key Terms & Concepts
- PLUGGYAPE: In this article, PLUGGYAPE refers to malware used in cyber attacks targeting Ukrainian defense forces.
- Void Blizzard: Void Blizzard is a Russian hacking group attributed with the cyber attacks involving PLUGGYAPE malware.
- WebSocket: WebSocket is a protocol that allows for full-duplex communication channels over a single TCP connection.
- MQTT: MQTT is a lightweight messaging protocol used for small sensors and mobile devices optimized for high-latency or unreliable networks.
- C2 (Command and Control): C2 refers to the infrastructure used by attackers to maintain communication with compromised systems.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.