Threats Tagged 'eastern europe'
View all threats tagged with 'eastern europe'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'eastern europe'
Click on any threat for detailed analysis and mitigation recommendations
A Russian APT group has been conducting targeted phishing campaigns against government entities in the Baltic and Balkan regions since at least 2023. The attackers use spoofed email attachments mimicking official documents to trick victims into submitting credentials on sophisticated fake login pages. These phishing pages feature blurred backgrounds and complex password validation, yet stolen credentials are exfiltrated regardless of password strength. The campaign specifically targets countries including Moldova, Ukraine, Lithuania, Bosnia and Herzegovina, Macedonia, Montenegro, Spain, and Bulgaria. The stolen credentials are sent to third-party services, enabling potential unauthorized access to sensitive government systems. This ongoing campaign poses a medium-level threat due to its targeted nature and potential for credential theft leading to further compromise. Defenders should focus on phishing awareness, email filtering, and credential monitoring to mitigate risks. The threat is particularly relevant to European government organizations in the affected regions due to geopolitical tensions and strategic importance. Join the discussion | AlienVault OTX General | 12/16/2025, 09:50:18 UTC Added: 12/16/2025, 12:47:12 UTC |
The Brazilian Caminho loader is a sophisticated malware delivery mechanism active since March 2025, leveraging LSB steganography to hide . NET payloads within images hosted on legitimate platforms. It initiates infection via phishing emails containing malicious scripts that download these steganographic images. The loader executes payloads filelessly in memory and establishes persistence using scheduled tasks. Caminho operates as a Loader-as-a-Service, delivering multiple malware families such as Remcos RAT, Xworm, and Katz stealer across South America, Africa, and Eastern Europe. Its use of bulletproof hosting and Portuguese language artifacts indicates a Brazilian origin and professional operation. The campaign targets multiple industries opportunistically without a specific sector focus. The infection chain employs multiple advanced techniques including fileless execution, steganography, and obfuscation, complicating detection and mitigation efforts. European organizations, especially in Eastern Europe, face risks of data theft, espionage, and system compromise. Mitigation requires targeted email security, memory scanning, and monitoring of scheduled tasks for persistence. Join the discussion | AlienVault OTX General | 10/22/2025, 04:00:17 UTC Added: 10/22/2025, 12:09:03 UTC |
This report examines recent activities attributed to the XDSpy threat actor, focusing on an ongoing campaign targeting Eastern European and Russian governmental entities using the XDigo malware since March 2025. The investigation stemmed from analyzing a vulnerability in LNK files, leading to the discovery of a multi-stage infection chain. The report provides analysis of the XDigo implant and its connections to previous XDSpy activities. It also details the exploitation of LNK parsing issues and infrastructure used across different campaigns. The research uncovered additional, more recent XDSpy activity employing an alternative infection chain. Targets include government entities in Eastern Europe, with a confirmed victim in Belarus. Join the discussion | AlienVault OTX General | 06/26/2025, 21:26:15 UTC Added: 06/26/2025, 21:34:55 UTC |
Showing 1 to 3 of 3 results