Ukrainian researchers warn of mobile malware targeting military and government officials

Published:

Ukrainian researchers have issued a warning regarding a surge in mobile malware targeting military personnel and government officials, as detailed in a report from the State Service of Special Communications and Information Protection (SSSCIP). The report highlights the increasing sophistication of Russian hackers, who are employing malicious applications and advanced exploits to compromise both Android and iOS devices.

The SSSCIP noted that the growing reliance on smartphones for communication among military and government personnel makes these devices prime targets for espionage and financially motivated attacks. Researchers stated, “The growing role of smartphones in communications among military personnel, government employees and civilians makes them increasingly attractive targets for intelligence gathering.”

Exploits and Attack Techniques

One notable tool identified in these attacks is DarkSword, an exploit kit specifically designed to target iPhones. DarkSword has been utilized in watering-hole attacks, where hackers compromise legitimate websites frequented by their intended victims. In Ukraine, attackers have successfully exploited vulnerabilities in Apple’s Safari browser and iOS by targeting news and government websites.

This method allows for the infection of iPhones with minimal action required from the victim. Once compromised, hackers can access sensitive information such as login credentials, messages, contacts, and call histories. Previous investigations have linked DarkSword’s activity to a suspected Russia-aligned hacking operation, with cybersecurity firm Lookout reporting that a threat actor known as UNC6353 has been using this exploit against Ukrainian users since at least late 2025.

Emerging Threat Groups

In addition to DarkSword, Ukrainian authorities have identified two new hacking groups, UAC-0244 and UAC-0263, which have been distributing malicious Android applications through deceptive websites aimed at Ukrainian users. UAC-0244 has created sites masquerading as the Ukraine’s 3rd Army Corps and other services, enticing visitors to engage with fake tests. This group has been linked to the distribution of CamelSpy malware, which collects extensive information from infected devices, including location data, contacts, and stored images.

Meanwhile, UAC-0263 has employed decoy websites offering fake applications for air raid alerts and fuel discounts. Their malware, known as BTMOB, enables remote access to infected devices, allowing hackers to steal sensitive information.

Broader Cyber Activity Trends

The mobile malware campaigns are part of a larger trend of cyber activity targeting Ukraine. The country’s national computer emergency response team, CERT-UA, reported 3,137 cyber incidents in the first half of 2026, marking an 8 percent increase compared to the previous six months. This uptick underscores the ongoing cyber threats faced by Ukraine amidst its ongoing conflict.

As the situation evolves, the implications for cybersecurity in Ukraine remain significant, with both military and governmental entities needing to bolster their defenses against these sophisticated mobile threats.

For further details, refer to the report from The Record.

For more insights on global cybersecurity developments, visit our Global cybersecurity coverage.

CHAPTER X // CYBER AWARENESS CAMPAIGN
BEYOND THE BALLROOM
[C://ME] // CHAPTER X

REQUEST THE MEDIA KIT

Tell us where to send the Beyond the Ballroom media deck. Every field is required.

We will use these details to respond to your media-kit request. Privacy Policy

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Star Blizzard evolves phishing tactics with new RedFlick malware delivery technique

In a significant evolution of its cyber operations, the Russian state-sponsored threat actor known as Star Blizzard has refined its phishing tactics and malware...

Data Dynamics CEO emphasizes importance of data sovereignty for cybersecurity in the Middle East

Data sovereignty has emerged as a critical focus for cybersecurity in the Middle East, according to Piyush M, CEO of Data Dynamics. In a...

FBI investigates alleged ShinyHunters hack targeting employee data amid threats

The FBI is currently investigating claims made by the hacking group ShinyHunters, which alleges it has accessed sensitive employee data from a major jobs...

Kubernetes operators expose security risks through excessive RBAC permissions, warns OperTraitor analysis

Kubernetes operators, designed to automate site reliability tasks, are increasingly exposing organizations to security vulnerabilities due to excessive role-based access control (RBAC) permissions. A...