The agency noted that a fake Telegram chat bot poses as technical support for the Reserve+ app, which is used by Ukrainian citizens to update their military registration.
The perpetrators use the account @reserveplusbot, pretending to be an official support account, and send messages urging users to install "special software."
According to the government response team CERT-UA, the harmful program, contained in the archive reservplus.zip, is a known computer virus called MeduzaStealer, which steals files from the victim's devices.
This bot was a legitimate support contact for Reserve+ as recently as May 2024, but it has since become a tool for malicious actors. CERT-UA has already taken steps to minimize the threat. Users are urged not to interact with the @reserveplusbot or download any files sent by it.