Malware spreads on Telegram, mimicking Ukraine’s Reserve+ app

17 October 2024, 01:19 AM

Harmful software has appeared on Telegram, disguised as Ukraine’s Reserve+ military registration app, Special Communications Service reported on Oct. 16.

The agency noted that a fake Telegram chat bot poses as technical support for the Reserve+ app, which is used by Ukrainian citizens to update their military registration.

The perpetrators use the account @reserveplusbot, pretending to be an official support account, and send messages urging users to install "special software."

Ad

According to the government response team CERT-UA, the harmful program, contained in the archive reservplus.zip, is a known computer virus called MeduzaStealer, which steals files from the victim's devices.

This bot was a legitimate support contact for Reserve+ as recently as May 2024, but it has since become a tool for malicious actors. CERT-UA has already taken steps to minimize the threat. Users are urged not to interact with the @reserveplusbot or download any files sent by it.

The military war may be swinging in our favor, but the information war continues.

Just as an army needs soldiers, so does a free society need its journalists to ensure that people have access to honest, trustworthy voices to understand the world around them.

For the past five years, The New Voice of Ukraine has been working tirelessly to push back against Russian narratives and defend democracy. But we cannot do it alone.

Please consider supporting us on Patreon for just $5 a month – your donation does directly to supporting journalists and ensuring that this front of the infowar says solid and defended.

Thank you.

Follow us on Twitter, Facebook and Google News

Show more news