Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
government-diplomatic-threatstate-sponsored-espionagephishing-campaign-intelligenceremote-access-implant

Void Blizzard (Laundry Bear) Charity-Themed Lures Deliver PluggyApe Backdoor to Ukraine’s Defense Forces

Updated 3mo agoFirst seen Jan 14, 20267 sources

Ukraine’s CERT (CERT-UA) reported a cyber-espionage campaign targeting representatives of Ukraine’s Defense Forces between October and December 2025, using social-engineering lures themed around charitable foundations. Victims were contacted via Signal and WhatsApp and directed to charity-impersonation websites or sent password-protected archives that purported to contain documents but instead delivered executable payloads (including *.docx.pif), sometimes sent directly through the messaging apps.

The activity was attributed with medium confidence to the Russia-aligned threat actor Void Blizzard (also tracked as Laundry Bear and UAC-0190). The campaign deployed a previously undocumented backdoor dubbed PluggyApe, built as a Python executable packaged with PyInstaller, which profiles infected hosts, establishes persistence via Windows Registry modification, and enables remote command execution. CERT-UA noted an evolution in late 2025 from earlier loader naming patterns (e.g., *.pdf.exe) to PIF-based delivery and an updated PluggyApe v2 featuring stronger obfuscation, MQTT-based command-and-control, and additional anti-analysis checks.

Share:
Void Blizzard (Laundry Bear) Charity-Themed Lures Deliver PluggyApe Backdoor to Ukraine’s Defense Forces
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Jan 13, 20265mo ago

CERT-UA discloses PluggyApe campaign and attributes it to Void Blizzard

In January 2026, CERT-UA publicly reported the campaign targeting Ukraine's Defense Forces and attributed it with medium confidence to the Russian-linked group Void Blizzard, also known as Laundry Bear or UAC-0190. The agency described the use of trusted messaging platforms, Ukrainian-language social engineering, and fake charity themes as part of a broader shift away from mass phishing.

Dec 1, 20257mo ago

PluggyApe campaign evolves with new PIF lures and v2 malware

By December 2025, the operators shifted to PIF-based payload delivery and deployed PluggyApe v2 with stronger obfuscation, anti-analysis or virtual-machine checks, and MQTT support. The malware also moved toward retrieving encoded command-and-control addresses from public paste services such as Pastebin and Rentry.

Oct 1, 20259mo ago

Attackers use early PluggyApe loader and Pastebin-based delivery

In October 2025, CERT-UA observed earlier activity using a '.pdf.exe' loader that fetched a Python interpreter and an early PluggyApe script from Pastebin. This reflects the campaign's initial delivery and command infrastructure approach before later refinements.

Void Blizzard begins charity-themed targeting of Ukraine's Defense Forces

Between October and December 2025, personnel in Ukraine's Defense Forces were targeted in a cyber-espionage campaign using Signal and WhatsApp messages that impersonated charitable organizations. Victims were lured to fake charity sites or sent password-protected archives containing disguised executables that installed the PluggyApe backdoor.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Affected products
12 linked
WindowsWhatsappSignal7-Zip7-ZipTelegramGmailPowershellPythonGmailGmailGmail
Organizations
13 linked
PastebinMeta PlatformsSignal MessengerMyBBVaronisMicrosoft CorporationSky ECCRentryBleepingComputerUkr.netRecorded FutureTelegramGoogle
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Void Blizzard (Laundry Bear) Charity-Themed Lures Deliver PluggyApe Backdoor to Ukraine’s Defense Forces | Mallory