Threats Tagged 'russia'
View all threats tagged with 'russia'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'russia'
Click on any threat for detailed analysis and mitigation recommendations
A new campaign targeting Ukrainian entities has been identified, attributed to actors linked to Russia. The campaign uses judicial and charity-themed lures to deploy a JavaScript-based backdoor called DRILLAPP, which runs through the Edge browser. This backdoor enables various actions including file manipulation, microphone access, and webcam capture. Two variants of the campaign have been observed, with the second variant introducing additional capabilities. The attackers utilize the browser's capabilities to evade detection and gain access to sensitive resources. The campaign shares tactics with a previously reported Laundry Bear operation, leading to a low-confidence attribution to this group. Join the discussion | AlienVault OTX General | 03/17/2026, 11:01:38 UTC Added: 03/17/2026, 11:27:29 UTC |
This article explores the misuse of QR codes in phishing attacks, focusing on three key areas: QR codes with URL shorteners concealing malicious destinations, in-app deep links used to steal credentials and control victims' apps, and QR codes bypassing app store security via direct malicious app downloads. The research reveals an average of 11,000 daily detections of malicious QR codes, with financial services being the most targeted industry. Attackers are leveraging QR code shorteners, in-app deep links, and direct downloads to evade security controls and exploit users' trust in QR codes. The article highlights specific attack scenarios, including account takeovers through messaging apps and distribution of suspicious gambling apps. Join the discussion | AlienVault OTX General | 02/14/2026, 03:41:01 UTC Added: 02/16/2026, 10:49:11 UTC |
A new hacking group called Punishing Owl has emerged, targeting Russian critical infrastructure. Their first attack on December 12, 2025, compromised a Russian state security agency, leaking internal documents. The group used DNS manipulation, created fake subdomains, and sent phishing emails to the victim's partners. They employed a PowerShell stealer called ZipWhisper to exfiltrate browser data. Punishing Owl's attacks are politically motivated and focus exclusively on Russian targets, including government agencies, scientific institutions, and IT organizations. The group has established a presence on cybercriminal forums and social media, likely operating from Kazakhstan. Experts predict this group will continue to be a persistent threat in the Russian cyberspace. Join the discussion | AlienVault OTX General | 02/04/2026, 15:26:42 UTC Added: 02/04/2026, 21:00:08 UTC |
A new cluster is spreading malware through phishing attacks targeting Russia. The attack methodology involves fake pages that imitate file downloads from Telegram. The article likely details the structure of these attacks, providing insights into how the malicious actors are exploiting user trust in the popular messaging platform to deliver their payload. This emerging threat, dubbed Vortex Werewolf, appears to be a sophisticated campaign specifically targeting Russian users or entities. Join the discussion | AlienVault OTX General | 01/29/2026, 07:39:26 UTC Added: 01/29/2026, 07:50:59 UTC |
A sophisticated multi-stage malware campaign targeting Windows users in Russia has been identified. The attack chain begins with social engineering lures and progresses to a full system compromise, including security bypass, surveillance, and ransomware delivery. It abuses Defendnot to disable Microsoft Defender and uses modular hosting across cloud services. The attack employs various techniques such as PowerShell scripts, obfuscated VBScript, and COM object manipulation. It deploys Amnesia RAT for data theft and surveillance, Hakuna Matata ransomware for file encryption, and a WinLocker component for system lockout. The campaign demonstrates how full system compromise can be achieved without exploiting software vulnerabilities, instead relying on social engineering and abuse of legitimate Windows features. Join the discussion | AlienVault OTX General | 01/20/2026, 17:50:42 UTC Added: 01/20/2026, 18:21:00 UTC |
Operation MoneyMount is a Russian phishing campaign targeting finance and accounting sectors by delivering Phantom stealer malware through fake payment confirmation emails. The attack uses a ZIP file containing an ISO image; when mounted, it reveals an executable that loads the stealer. Phantom stealer employs anti-analysis techniques and steals sensitive data including cryptocurrency wallets, browser data, and Discord tokens. It also features keylogging and clipboard monitoring to capture additional credentials and information. Stolen data is exfiltrated via Telegram, Discord webhooks, or FTP, making detection and blocking more challenging. The use of ISO files for initial access helps evade traditional security controls. This campaign highlights the growing sophistication of commodity stealers and the strategic targeting of financial sectors. No known exploits in the wild or CVE identifiers are associated with this malware yet. The campaign’s medium severity reflects its targeted nature and complexity of attack chain. Join the discussion | AlienVault OTX General | 12/12/2025, 08:45:04 UTC Added: 12/12/2025, 13:12:01 UTC |
The Silent Lynx APT group has been conducting espionage campaigns targeting Central Asian nations, Russia, China, and Azerbaijan. Two main campaigns were identified: one focusing on Russia-Azerbaijan relations and another on China-Central Asia relations. The group uses various malware including PowerShell scripts, .NET implants, and C++ reverse shells. They leverage spear-phishing with malicious attachments, GitHub-hosted payloads, and scheduled tasks for persistence. The campaigns aim to gather intelligence on diplomatic communications, transportation projects, and other strategic initiatives. Silent Lynx shows a pattern of targeting summit meetings and infrastructure deals in the region, with a particular focus on events in Dushanbe, Tajikistan. Join the discussion | AlienVault OTX General | 11/05/2025, 12:36:24 UTC Added: 11/05/2025, 21:32:54 UTC |
The Silent Lynx APT group has been conducting espionage campaigns targeting diplomatic entities and critical infrastructure in Central Asia, Russia, and China. Two major campaigns were identified: one focused on Russia-Azerbaijan relations and another on China-Central Asia relations. The group used various malware tools including PowerShell scripts, .NET implants, and C++ reverse shells. They leveraged spear-phishing emails with malicious attachments and GitHub-hosted payloads. Key targets included government think-tanks, diplomats, and entities in mining, transport and communication industries. The campaigns coincided with important summits and meetings between the targeted countries. Attribution was based on similarities in tactics, tools, and victimology to previous Silent Lynx operations. Join the discussion | AlienVault OTX General | 11/03/2025, 14:02:52 UTC Added: 11/03/2025, 20:00:46 UTC |
A sophisticated campaign targeting Russian and Belarusian military personnel has been identified, using multi-stage infection chains and decoy documents. The attackers deploy OpenSSH and Tor bridges to establish covert remote access and lateral movement capabilities. The infection process involves PowerShell scripts, scheduled tasks for persistence, and the use of Tor hidden services to expose multiple local services. The campaign employs anti-analysis techniques and leverages obfuscated configurations for SSH and Tor. While attribution remains uncertain, the targeting and tactics are consistent with Eastern European-linked espionage activities focusing on defense and government sectors. Join the discussion | AlienVault OTX General | 10/31/2025, 21:01:40 UTC Added: 10/31/2025, 21:35:48 UTC |
A spear-phishing campaign targeting the Russian Automobile-Commerce industry using a malicious.NET implant has been uncovered by Seqrite Labs Research Team and is now being investigated by the FBI. Join the discussion | AlienVault OTX General | 10/17/2025, 15:59:18 UTC Added: 10/17/2025, 16:01:39 UTC |
Showing 1 to 10 of 20 results