In the final months of 2025, the Ukrainian Defense Forces were targeted by a sophisticated cyber espionage campaign. According to several cybersecurity analysts, the attack used social engineering techniques to infiltrate Ukrainian military systems. This incident represents yet another example of how the Russian-Ukrainian conflict continues to develop on the digital front as well.
The attack, which occurred between October and December 2025, exploited a targeted phishing strategy through Signal and WhatsApp messaging applications. The attackers posed as charitable organizations, sending seemingly legitimate messages to members of the Ukrainian armed forces. These messages contained malicious files which, once opened, installed sophisticated malware called “PluggyApe”. This backdoor, based on Python language and packaged with PyInstaller, used deceptive file names like “.pdf.exe” or “.docx.pif” to appear as harmless documents. Once installed, the malware provided attackers with persistent remote access to compromised systems, allowing them to profile devices, execute commands, and steal sensitive data.
The potential impact of this attack is particularly serious considering the war context. Unauthorized access to Ukrainian armed forces’ systems could compromise strategic information, military plans, and critical operational data. The ability to execute commands on compromised systems could also allow attackers to sabotage operations or gather intelligence in real-time, creating a significant tactical advantage.
To protect against similar attacks, military and civilian organizations should strengthen cybersecurity training programs, raising awareness among personnel about phishing risks. It is essential to always verify the authenticity of senders before opening attachments, especially if they come from unofficial communication channels. The use of advanced security solutions to detect malware and the implementation of multi-factor authentication can provide additional layers of protection against these threats.
- Key points to remember:
- The attack has been attributed with medium confidence to the “Void Blizzard” group (also known as “Laundry Bear” or “UAC-0190”), believed to be linked to Russia.
- The phishing technique via messaging apps represents an evolution in cyber espionage tactics, exploiting channels generally considered secure.
- This incident highlights how cyber warfare operations continue to represent a critical component in modern conflicts.
- Sources:
- https://www.cybersecurity-help.cz/blog/5171.html
- https://securityaffairs.com/186910/intelligence/cert-ua-reports-pluggyape-cyberattacks-on-defense-forces.html
- https://www.bleepingcomputer.com/news/security/ukraines-army-targeted-in-new-charity-themed-malware-campaign/
- https://thehackernews.com/2026/01/pluggyape-malware-uses-signal-and.html
Source: SentinelOne