Google Threat Intelligence Group reported that suspected Russian operation UNC5812 used a hybrid espionage-and-influence campaign to target potential Ukrainian military recruits through a Telegram persona and a website branded "Civil Defense." Promoted posts in legitimate Ukrainian-language Telegram channels lured users to actor-controlled infrastructure that pushed anti-mobilization narratives, solicited videos alleging abuse by Ukrainian recruitment centers, and amplified messaging aligned with broader pro-Russian influence networks.
The operation also delivered malware to both Windows and Android users. Windows victims were led through a multi-stage infection chain involving Pronsis Loader—a JPHP-based malware family also documented by Trustwave as distinct from D3F@ck Loader—before deployment of PURESTEALER, while Android users were tricked into disabling Google Play Protect and granting permissions needed for CRAXSRAT; researchers also identified a decoy mapping application tracked as SUNSPINNER. Google said it added related files and infrastructure to Safe Browsing, relied on Play Protect protections, and shared findings with Ukrainian authorities, who blocked national resolution of the Civil Defense site.

TTPs, infrastructure, and targeting history in one profile.
6 events from the most recent confirmed update back to the earliest known activity.
Another Ukrainian-language news channel promoted Civil Defense posts, showing the operation was still being amplified through Telegram channels in October 2024.
A legitimate Ukrainian missile alert Telegram channel with more than 80,000 subscribers promoted the Civil Defense operation, helping drive users to actor-controlled infrastructure.
Google Threat Intelligence Group discovered UNC5812, which it assessed as a suspected Russian hybrid espionage and influence operation targeting Ukrainian military recruits.
The Telegram channel @civildefense_com_ua was created and later used as a lure hub for the operation's malware delivery and anti-mobilization messaging.
The actor-controlled Civil Defense website domain, civildefense[.]com.ua, was registered as part of the infrastructure later used to target potential Ukrainian military recruits.
Google added identified infrastructure and files to Safe Browsing, shared its findings with Ukrainian authorities, and Ukrainian authorities blocked national resolution of the Civil Defense website.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 16 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
cloud.google.com
Open sourcetrustwave.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.