PLUGGYAPE Malware: Ukraine Defense Forces Targeted via Signal & WhatsApp

by priyanka.patel tech editor

Russian Hackers Intensify Attacks on Ukraine’s Defense Forces with Sophisticated Malware

A surge in cyberattacks targeting Ukraine’s defense sector has been attributed to Russian-linked threat actors, utilizing increasingly sophisticated malware and leveraging popular messaging apps for initial compromise. The Computer Emergency Response Team of Ukraine (CERT-UA) detailed a series of attacks between October and December 2025 involving malware known as PLUGGYAPE, highlighting a growing trend of targeted espionage.

Escalating Cyber Warfare in Ukraine

The attacks, with medium confidence attributed to the hacking group Void Blizzard (also known as Laundry Bear or UAC-0190), represent a important escalation in cyber warfare coinciding with ongoing geopolitical tensions. According to CERT-UA,Void Blizzard has been active as at least April 2024,consistently refining its tactics and tools.

These attacks are characterized by a high degree of operational security (OPSEC), audio and video communication, and the attacker may demonstrate detailed and relevant knowledge about the individual, organization, and its operations,” a CERT-UA representative stated. This level of sophistication suggests a well-resourced and highly motivated adversary.

PLUGGYAPE: A Persistent and Evolving Threat

PLUGGYAPE, writen in Python, is a backdoor that establishes communication with remote servers using WebSocket or Message queuing Telemetry Transport (MQTT). This allows attackers to execute arbitrary code on infected machines. CERT-UA noted that successive versions of the malware have incorporated obfuscation and anti-analysis checks to evade detection by security software and prevent execution within virtualized environments.

The malware’s command-and-control (C2) infrastructure is particularly resilient. Instead of hardcoding C2 addresses directly into the malware, attackers retrieve them from external paste services like rentry[.]co and pastebin[.]com, encoded in Base64. This allows for rapid updates to the C2 servers, mitigating the impact of detection and takedown efforts.

Expanding Attack Surface: Additional Threat Actors and Malware

Beyond PLUGGYAPE, CERT-UA has identified activity from other threat clusters. UAC-0239 has been deploying phishing emails from UKR[.]net and Gmail addresses containing links to a VHD file or direct attachments, leading to the installation of FILEMESS, a Go-based stealer designed to exfiltrate files to Telegram. This cluster also utilizes the open-source OrcaC2 framework for system manipulation, file transfer, and keylogging. These attacks have specifically targeted Ukrainian defense forces and local governments.

Another group, UAC-0241, is conducting spear-phishing campaigns against educational institutions and state authorities, employing ZIP archives containing malicious Windows shortcut (LNK) files. Opening these files triggers the execution of an HTML Application (HTA) via “mshta.exe,” which then downloads and executes a PowerShell script. this script delivers LaZagne,an open-source tool for password recovery,and GAMYBEAR,a Go backdoor capable of receiving and executing commands from a server and transmitting results in Base64-encoded form over HTTP.

The Rise of Messengers as Cyber Threat Channels

The increasing reliance on widely used messaging applications for cyberattacks is a concerning trend. As CERT-UA emphasized, “widely used messengers available on mobile devices and personal computers are de facto becoming the most common channel for delivering software tools for cyber threats.” This shift underscores the need for heightened vigilance and improved security awareness among potential targets.

The evolving tactics and persistent activity of these Russian-linked threat actors demonstrate a continued commitment to cyber espionage and disruption within Ukraine, posing a significant challenge to the nation’s cybersecurity defenses.

You may also like

Leave a Comment