Russian malware campaign
In September 2024, Google Threat Analysis Group (TAG) and Mandiant discovered “UNC5812,” a suspected hybrid Russian espionage and influence campaign that spreads Windows and Android malware via a Telegram persona named “Civil Defense.” “Civil Defense” claims to be a provider of free software programs that allow prospective draftees to view and share the locations of Ukrainian military recruiters. When installed with Google Play Protect disabled, these programs deliver an operating system-specific commodity malware variant to the victim along with a mapping application we identify as SUNSPINNER. The actors behind UNC5812 leverage both the…