loader image
CERT‑UA links PLUGGYAPE attacks: hooded ape with plug-tail, holographic green binary screens, python motif, network nodes.
CERT‑UA Links PLUGGYAPE Attacks to Void Blizzard

Ukraine’s Computer Emergency Response Team, CERT-UA, links the PluggyApe attacks targeting the country’s defense forces to a Russia-associated hacking group known as Void Blizzard. The threat actors leveraged social engineering tactics through messaging apps to lure victims onto fake charitable websites. These sites pushed malicious files masked as harmless documents using misleading extensions such as “.docx.pif.”

Once executed, the malware installs the PluggyApe backdoor, built in Python and packaged with PyInstaller. Later versions of the tool use MQTT protocol for covert communication and include features to avoid detection, such as virtual machine checks. Attackers often hide command server data on public paste services using encoded formats.

PluggyApe maintains persistence by modifying registry keys and identifying infected devices via SHA-256 fingerprints. CERT-UA warns that attackers now exploit Ukrainian mobile numbers and language to gain victims’ trust during initial contact.

CERT-UA links PluggyApe attacks to the same group involved in prior breaches across Europe.

CERT-UA reports PLUGGYAPE cyberattacks on defense forces

Write a Reply or Comment

Your email address will not be published. Required fields are marked *