Ukrainian researchers have issued a warning regarding a surge in mobile malware targeting military personnel and government officials, as detailed in a report from the State Service of Special Communications and Information Protection (SSSCIP). The report highlights the increasing sophistication of Russian hackers, who are employing malicious applications and advanced exploits to compromise both Android and iOS devices.
The SSSCIP noted that the growing reliance on smartphones for communication among military and government personnel makes these devices prime targets for espionage and financially motivated attacks. Researchers stated, “The growing role of smartphones in communications among military personnel, government employees and civilians makes them increasingly attractive targets for intelligence gathering.”
Exploits and Attack Techniques
One notable tool identified in these attacks is DarkSword, an exploit kit specifically designed to target iPhones. DarkSword has been utilized in watering-hole attacks, where hackers compromise legitimate websites frequented by their intended victims. In Ukraine, attackers have successfully exploited vulnerabilities in Apple’s Safari browser and iOS by targeting news and government websites.
This method allows for the infection of iPhones with minimal action required from the victim. Once compromised, hackers can access sensitive information such as login credentials, messages, contacts, and call histories. Previous investigations have linked DarkSword’s activity to a suspected Russia-aligned hacking operation, with cybersecurity firm Lookout reporting that a threat actor known as UNC6353 has been using this exploit against Ukrainian users since at least late 2025.
Emerging Threat Groups
In addition to DarkSword, Ukrainian authorities have identified two new hacking groups, UAC-0244 and UAC-0263, which have been distributing malicious Android applications through deceptive websites aimed at Ukrainian users. UAC-0244 has created sites masquerading as the Ukraine’s 3rd Army Corps and other services, enticing visitors to engage with fake tests. This group has been linked to the distribution of CamelSpy malware, which collects extensive information from infected devices, including location data, contacts, and stored images.
Meanwhile, UAC-0263 has employed decoy websites offering fake applications for air raid alerts and fuel discounts. Their malware, known as BTMOB, enables remote access to infected devices, allowing hackers to steal sensitive information.
Broader Cyber Activity Trends
The mobile malware campaigns are part of a larger trend of cyber activity targeting Ukraine. The country’s national computer emergency response team, CERT-UA, reported 3,137 cyber incidents in the first half of 2026, marking an 8 percent increase compared to the previous six months. This uptick underscores the ongoing cyber threats faced by Ukraine amidst its ongoing conflict.
As the situation evolves, the implications for cybersecurity in Ukraine remain significant, with both military and governmental entities needing to bolster their defenses against these sophisticated mobile threats.
For further details, refer to the report from The Record.
For more insights on global cybersecurity developments, visit our Global cybersecurity coverage.


