Ukraine’s Defense Forces Targeted by Charity-Themed Malware Campaign
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
In late 2025, Ukraine’s Defense Forces faced a targeted cyberattack involving the backdoor malware PluggyApe. The campaign, attributed to the Russian threat groups Void Blizzard and Laundry Bear, occurred between October and December. Attackers used instant messaging platforms like Signal and WhatsApp to send messages that directed recipients to a fake charity website, where they were prompted to download a password-protected archive containing malicious executable files.
PluggyApe is designed to profile infected hosts, send information back to the attackers, and wait for further commands. The malware achieves persistence by modifying the Windows Registry. The attackers have evolved their methods, switching from using the ‘.pdf.exe’ extension to PIF files starting in December 2025, enhancing their obfuscation techniques and communication methods.
The Ukrainian Computer Emergency Response Team (CERT-UA) reported that the malware fetches command-and-control addresses from external sources, making it harder to detect. This incident underscores the growing threat to military and governmental organizations, particularly as attackers leverage compromised accounts and local language to enhance the credibility of their attacks.
Implications for Cybersecurity
This incident reveals a concerning trend in cyber warfare, where attackers employ social engineering tactics to exploit trust. The use of legitimate accounts and local language makes these attacks particularly convincing, posing significant risks to organizations. Users should be vigilant about unexpected messages, especially those urging them to download files.
Organizations, especially those in sensitive sectors, must enhance their cybersecurity awareness and training. Regularly updating software and monitoring for unusual activity can help mitigate risks associated with such sophisticated attacks. Additionally, implementing multi-factor authentication can provide an extra layer of security against unauthorized access.
As mobile devices are increasingly targeted due to their weaker security, users should ensure their devices are protected with strong passwords and updated security measures. Awareness of the tactics used by attackers can help individuals and organizations better prepare for potential threats.
- PluggyApe: A backdoor malware that profiles hosts and waits for commands.
- Void Blizzard: A Russian threat group linked to cyberattacks against NATO member states.
- Laundry Bear: The same group responsible for breaching Dutch police systems in 2024.
- Signal: A messaging app used by attackers to deliver malicious messages.
- WhatsApp: Another platform exploited for sending deceptive messages.
Key Takeaways
- Be cautious of unexpected messages on messaging apps that prompt downloads, especially from unknown contacts.
- Regularly update your software and operating systems to protect against known vulnerabilities.
- Implement multi-factor authentication on all accounts to enhance security against unauthorized access.
- Educate yourself and your team about social engineering tactics to recognize potential phishing attempts.
- Monitor your devices for unusual activity and report any suspicious behavior to your IT department.
Key Terms & Concepts
- PluggyApe: In this article, PluggyApe refers to a backdoor malware that profiles infected hosts and communicates with attackers.
- Void Blizzard: Void Blizzard is a Russian threat group known for targeting NATO member states in cyberattacks.
- Laundry Bear: Laundry Bear is a Russian cyber threat group linked to breaches of sensitive systems, including those of the Dutch police.
- PIF file: A PIF file is an executable file format that can be used to deliver malware disguised as legitimate documents.
- Social engineering: Social engineering is a tactic used by attackers to manipulate individuals into divulging confidential information.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.