Google researchers have discovered a unique hybrid espionage/influence campaign, carried out by Russian hackers “UNC5812,” targeting newly recruited Ukrainian soldiers with malware for Windows and Android systems.

According to Google, the campaign impersonated a “Civil Defense” persona using a related website and a dedicated Telegram channel . A fake recruitment avoidance app dubbed “Sunspinner” by researchers was used to distribute the malware
The campaign targets Windows and Android devices using separate malware for each platform. Russian hackers UNC5812 can use the malware to steal data and spy on Ukrainians in real time.
Google has taken steps to prevent malicious activity.
Fake persona "Civil Defense"
Russian hackers UNC5812 did not attempt to impersonate the Civil Defense of Ukraine or any other government agency. They promoted the Civli Defense persona as a legitimate, pro-Ukrainian organization that provides Ukrainian soldiers with useful software tools and advice.
See also: Russian hackers APT29 target Zimbra and TeamCity servers
The alleged organization uses a Telegram channel and website to attract potential victims and promote narratives against Ukraine's recruitment and mobilization efforts, aiming to instill distrust and resistance among the population.
When Google discovered the campaign on September 18, 2024, the “Civil Defense” channel on Telegram already had 80,000 members.
Users who visited the Civil Defense website were taken to a download page for a malicious application, promoted as a mapping tool that can help users track recruiter locations to avoid them.
Google calls this app “Sunspinner,” and although the app features a map with markers, Google says the data is fabricated. The app’s sole purpose is to hide the installation of malware that’s happening in the background.
Windows and Android malware
The fake apps target Windows and Android systems and promise to add support for iOS and macOS as well.
On Windows, it uses Pronsis Loader, a malware loader that retrieves additional malicious payloads from the Russian hackers' UNC5812 server, including the information-stealing tool "PureStealer".
See also: Russian hackers target Ukrainian military infrastructure
PureStealer targets information stored in web browsers, such as passwords , cookies, cryptocurrency wallet details, email clients, and messaging app data.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
On Android, the downloaded APK file installs the CraxsRAT backdoor. CraxsRAT allows attackers to track the victim's location in real time, log keystrokes, record audio, retrieve contact lists, access SMS messages, and steal files and credentials.

In fact, the app tricks users into disabling Google Play Protect. Google has updated Google Play's protections to detect and block Android malware early. It has also added domains and files associated with the campaign to the 'Safe Browsing' feature in Chrome.
The use of malware for both Windows and Android systems highlights the evolving nature of cyber threats .Russian hackers UNC5812 and cybercriminals in general are constantly adapting and simultaneously using different attack vectors to achieve their goals. As a result, organizations must remain vigilant and constantly update their security protocols to protect themselves from these evolving threats.
See also: Russian GRU hackers attack critical infrastructure
In addition to stealing sensitive information, influence campaigns play a critical role in shaping public opinion and manipulating individuals’ beliefs or behaviors. In this case, the propaganda spread by Russian hackers UNC5812 could undermine trust in the Ukrainian military and sow discord. It is important for individuals to be aware of these tactics and carefully evaluate the information they read.
The full list of breach indicators related to the latest Russian hacking campaign UNC5812 is available here.
Source: www.bleepingcomputer.com
