Ukrainian cybersecurity authorities have uncovered a sophisticated campaign where threat actors impersonate charitable organizations to deliver malware against military defense personnel.
Between October and December 2025, CERT-UA and Ukraine’s Armed Forces Cyber Response Team documented multiple targeted attacks utilizing the PLUGGYAPE backdoor malware, attributed with moderate confidence to the Void Blizzard group (also tracked as UAC-0190).

Attack Method and Deception Tactics
The attackers employ convincing social engineering tactics, using legitimate Ukrainian phone numbers and Ukrainian language communications to contact targets via messaging applications.
Victims receive messages directing them to fake charity websites designed to resemble legitimate humanitarian organizations.

These fraudulent sites offer document downloads, executable files often compressed in password-protected archives or distributed directly as “.docx.pif” files.
In October 2025, attackers used “.pdf.exe” files that deployed loaders designed to download Python interpreters and early versions of PLUGGYAPE.
By December, investigators discovered an improved, obfuscated PLUGGYAPE.V2 variant that incorporates the MQTT protocol and anti-analysis checks to prevent execution in virtual environments.

Analysis of the PLUGGYAPE backdoor reveals it was developed using Python and establishes connections to command-and-control servers via WebSockets or MQTT, with data transmitted in JSON format.
The malware generates unique device identifiers using SHA-256 hashing based on MAC addresses, BIOS serial numbers, and processor identifiers. Persistence is achieved by modifying the Windows Registry’s Run key.
Investigators identified command-and-control servers hosted at 193.23.216.39, 108.165.164.155, and 176.9.23.216, with additional infrastructure linked to counterfeit charity domains including hart-hulp-ua.com, solidarity-help.org, and saint-daniel variants.
Control server addresses were sometimes encoded in BASE64 format and published on Pastebin and Rentry.co to evade detection.
CERT-UA emphasizes that the threat landscape is continually evolving, with attackers demonstrating detailed knowledge of target organizations and individuals.
Ukrainian defense personnel should immediately report suspicious files, links, or communications to appropriate cybersecurity authorities.
Organizations without enterprise security solutions must exercise heightened vigilance when verifying the legitimacy of unsolicited communications and file downloads.
Military personnel should contact the Armed Forces Cyber Response Team at csoc@post.mil.gov.ua for suspected incidents.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.