Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » PLUGGYAPE malware uses Signal and WhatsApp to target Ukrainian Armed Forces
Celebrities

PLUGGYAPE malware uses Signal and WhatsApp to target Ukrainian Armed Forces

By January 14, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 14, 2026Ravi LakshmananCyber ​​espionage/threat intelligence

The Computer Emergency Response Team of Ukraine (CERT-UA) has revealed details of a new cyberattack targeting the Armed Forces between October and December 2025 with malware known as PLUGGYAPE.

This activity is believed with medium confidence to be the work of a Russian hacker group tracked as Void Blizzard (also known as Laundry Bear or UAC-0190). This threat actor is believed to have been active since at least April 2024.

Attack chains distributing malware use instant messaging Signal and WhatsApp as vectors, with attackers posing as charity organizations persuading targets to click on seemingly innocuous links (“harthulp-ua”)[.]com” or “Solidarity Help”[.]org”) impersonates the Foundation and downloads a password-protected archive.

The archive contains executable files created with PyInstaller that ultimately lead to the deployment of PLUGGYAPE. CERT-UA said that successive iterations of the backdoor added obfuscation and anti-analysis checks to prevent artifacts from being executed in virtual environments.

cyber security

Written in Python, PLUGGYAPE establishes communication with remote servers via WebSockets or Message Queue Telemetry Transport (MQTT), allowing operators to execute arbitrary code on compromised hosts. Support for communication using the MQTT protocol was added in December 2025.

Additionally, command and control (C2) addresses are obtained from external paste services such as rentry.[.]co and paste bin[.]com, rather than hard-coding the domain directly into the malware itself, it is stored in a base64-encoded format. This allows attackers to maintain operational security and resiliency, allowing them to update their C2 servers in real-time in scenarios where the original infrastructure is detected and down.

CERT-UA stated that “initial interactions with targets of cyberattacks are increasingly carried out using legitimate accounts and phone numbers of Ukrainian mobile carriers, using the Ukrainian language, voice and video communications, and attackers may demonstrate detailed and relevant knowledge of individuals, organizations and their operations.”

“Widely used messengers available on mobile devices and personal computers are becoming the de facto most common channel for delivering software tools against cyber threats.”

In recent months, cybersecurity agencies have also revealed that a threat cluster tracked as UAC-0239 sent phishing emails from UKR.[.]net and Gmail addresses containing links to VHD files (or directly as attachments) pave the way for a Go-based stealer called FILEMESS that collects files matching a specific extension and leaks them to Telegram.

It also dropped an open-source C2 framework called OrcaC2 that enables system operations, file transfers, keylogging, and remote command execution. The operation is said to have targeted the Ukrainian Armed Forces and local governments.

cyber security

Ukrainian educational institutions and state authorities have also fallen victim to another spear-phishing campaign organized by UAC-0241 that exploits ZIP archives containing Windows shortcut (LNK) files to trigger the execution of HTML applications (HTA) using ‘mshta.exe’.

The HTA payload then launches JavaScript designed to download and run PowerShell scripts, providing an open source tool called LaZagne to recover stored passwords, and a Go backdoor codenamed GAMYBEAR that can receive and execute commands received from the server and send the results over HTTP in Base64 encoded format.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleLargest crowdsourced search for alien information, data from collapsed Arecibo Observatory reveals 12 billion “signals of interest”
Next Article Critical vulnerability in Node.js could cause server crash via async_hooks stack overflow

Related Posts

Duchess Kate wears Patrick McDowell bespoke with Order of the Garter

June 15, 2026

Melania Trump shows off her high fashion look in Dolce & Gabbana at UFC 250

June 15, 2026

Laverne Cox brings back Mugler’s 2001 spider dress at Seattle Pride Gala

June 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Choose a new language (or 25 languages) with this $127 Rosetta Stone sale

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

Merlin, a common roadside duck in Mexico City, will be the World Cup mascot.

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

Trending Posts

Jelly Roll files for divorce from Bunny XO after 10 years of marriage

June 16, 2026

BTS is the group fans are most looking forward to seeing perform at the 2026 World Cup

June 15, 2026

Swimming Pole, Billboard’s Emerging Dance Artist of the Month

June 15, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.