Russian hackers posed as charities to install malware on Ukrainian military devices - Межа
Between November and December 2025, representatives of the Ukrainian Defense Forces were targeted by a new cyberattack disguised as a charitable foundation. According to the Ukrainian Computer Emergency Response Team (CERT-UA), the attack is likely being carried out by the Russian group Void Blizzard, also known as Laundry Bear.
The attacks installed PluggyApe malware on Ukrainian military devices. This is a backdoor that creates a host profile and sends information to attackers, including the victims’ unique identifier, and then waits for commands to execute code.
The attacks began with WhatsApp or Signal messages asking recipients to visit a website that purportedly belonged to a charitable foundation. There, they offered to download "documents" - executable files, which are usually in a password-protected archive. At the same time, the executable file can be sent directly to the messenger and usually has the extension ".docx.pif".
As CERT-UA notes, in October 2025, the attackers used a file with the .pdf.exe extension, which launched a loader designed to install an early version of PluggyApe. However, starting in December, they began using an improved version of the software, which uses the .docx.pif extension, and also used the MQTT protocol and added a number of checks to counteract analysis.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
