HomeSecurityPLUGGYAPE malware targets Ukraine via Signal & WhatsApp

PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed details of new cyberattacks targeting the country's defense forces with malware known as PLUGGYAPE. The attacks took place between October and December 2025.

PLUGGYAPE malware

This activity is attributed with moderate certainty to a Russian hacking group tracked as Void Blizzard (also known as Laundry Bear or UAC-0190). The threat actor is believed to have been active since at least April 2024.

How is PLUGGYAPE distributed?;

The attack chains that distribute the malware leverage instant messaging platforms such as Signal and WhatsApp, with threat actors posing as charities to convince targets to click on seemingly innocuous links (“harthulp-ua[.]com” or “solidarity-help[.]org”). Users are then prompted to download a password-protected archive.

See also: deVixor: New Android banking malware

The files contain an executable created with PyInstaller, which ultimately leads to the development of PLUGGYAPE. CERT-UA noted that successive versions of the backdoor have added obfuscation and anti-parsing checks to prevent the artifacts from running in a virtual environment.

PLUGGYAPE malware

Written in Python, PLUGGYAPE establishes communication with a remote server via WebSocket or Message Queuing Telemetry Transport (MQTT), allowing operators to execute arbitrary code on compromised systems. Support for communication using the MQTT protocol was added in December 2025.

PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

Additionally, command and control (C2) addresses are retrieved from external paste services such as rentry[.]co and pastebin[.]com, where they are stored in base64-encoded format. This approach allows attackers to maintain operational security and resilience and notify C2 servers in real time if the original infrastructure is detected and taken down.

See also: VoidLink: New malware framework targets Linux systems

CERT-UA stated that initial interactions with targets of cyberattacks are increasingly taking place through legitimate accounts and phone numbers of Ukrainian mobile operators, using the Ukrainian language and demonstrating detailed knowledge of the individual, the organization, and its operations.

Other attacks in Ukraine

The service also revealed that a threat cluster tracked as UAC-0239 sent phishing emails from UKR[.]net and Gmail addresses that contained links to a VHD (or directly as an attachment). This paves the way for a Go-based stealer called FILEMESS, which collects files matching certain extensions and exports them to Telegram.

Additionally, an open-source C2 framework, called OrcaC2, is installed allowing system manipulation, file transfers, keystroke logging , and remote command execution. This activity is said to have targeted Ukrainian defense forces and local governments.

See also: SHADOW#REACTOR: New campaign distributes Remcos RAT

PLUGGYAPE malware targets Ukraine via Signal & WhatsApp

Educational institutions and government authorities in Ukraine have also been targeted by another campaign spear-phishing organized by UAC-0241, which uses ZIP files containing a Windows shortcut (LNK) file. Opening this file causes an HTML application (HTA) to be executed using “mshta.exe.”

The HTA payload launches JavaScript, designed to download and execute a PowerShell script, which provides:

  • an open source tool called LaZagne, for recovering saved passwords
  • a backdoor, named GAMYBEAR, that can receive and execute incoming commands from a server and transmit the results back in Base64-encoded format, over HTTP.
Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS