Threats Tagged 'russian'
View all threats tagged with 'russian'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'russian'
Click on any threat for detailed analysis and mitigation recommendations
Fantasy Hub is a newly identified Android Remote Access Trojan (RAT) offered as Malware-as-a-Service (MaaS) on Russian-language platforms. It provides extensive espionage capabilities including SMS exfiltration, contact and call log theft, and bulk media extraction. The malware can intercept, reply to, and delete incoming notifications, and uses fake Google Play pages to evade detection. It specifically targets financial institutions by deploying fake windows to steal banking credentials. The MaaS model includes comprehensive documentation and a bot-driven subscription system, lowering the barrier for novice attackers. Although no known exploits in the wild have been reported yet, the threat poses a medium severity risk due to its broad capabilities and ease of use. European organizations, especially financial institutions, are at risk due to the malware’s targeting profile and Android’s widespread use. Mitigation requires targeted detection of fake app pages, enhanced mobile security hygiene, and user awareness focused on banking credential phishing. Countries with large financial sectors and high Android adoption, such as Germany, France, and the UK, are most likely to be affected. Join the discussion | AlienVault OTX General | 11/10/2025, 11:34:25 UTC Added: 11/10/2025, 11:50:41 UTC |
Forescout honeypot caught hacktivist activity targeting a decoy water treatment plant in Sept.2025. A Russian-aligned group, TwoNet, claimed responsibility for the attack. The group logged into the human-machine interface (HMI) for: defacement, process disruption, manipulation, and evasion. Join the discussion | AlienVault OTX General | 10/10/2025, 16:56:05 UTC Added: 10/10/2025, 17:10:27 UTC |
A sophisticated Android backdoor named Android.Backdoor.916.origin is targeting Russian business representatives. The malware, disguised as an antivirus app called 'GuardCB', has extensive surveillance capabilities including intercepting calls, streaming camera footage, stealing data from messaging apps and browsers, and keylogging. Distributed via messenger apps, it requests numerous system permissions and connects to C2 servers for commands. The backdoor can transmit SMS messages, contact lists, call logs, location data, and captured audio/video streams. It uses Accessibility Service to log keystrokes and intercept content from specific apps like Telegram and Chrome. The malware is believed to be used for targeted attacks rather than mass distribution. Join the discussion | AlienVault OTX General | 08/25/2025, 10:55:03 UTC Added: 08/25/2025, 11:17:38 UTC |
Showing 1 to 3 of 3 results