Threats Tagged 'russian-speaking'
View all threats tagged with 'russian-speaking'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'russian-speaking'
Click on any threat for detailed analysis and mitigation recommendations
A sophisticated multi-stage malware operation was identified through an exposed C2 panel at 103.241.66[.]238:1337, combining cryptocurrency clipboard hijacking across eight chains, BIP-39 seed phrase theft, browser credential exfiltration, ransomware module (crpx0), and Java RAT builder managed via FastAPI-based panel with license key system. The operation targets Windows and macOS using FedEx and OnlyFans-themed social engineering lures, with complete source code exposed in open directories. The ransomware component communicates with three Russian .ru domains resolving to 31.31.198[.]206 at REG.RU hosting, operating under the identity DataBreachPlus with Telegram, qTox, and ProtonMail contacts. Ten cryptocurrency wallet addresses spanning Bitcoin, Ethereum, Tron, Dogecoin, Litecoin, Solana, Ripple, and Bitcoin Cash were extracted from configurations, indicating a Malware-as-a-Service operation with tiered licensing. Join the discussion | AlienVault OTX General | 04/22/2026, 12:41:31 UTC Added: 04/22/2026, 15:31:05 UTC |
The Kraken ransomware group, originating from the HelloKitty cartel, conducts sophisticated big-game hunting and double extortion attacks targeting Windows, Linux, and VMware ESXi systems. They exploit SMB vulnerabilities for initial access and use tools like Cloudflared and SSHFS for persistence and data exfiltration. Kraken ransomware features advanced capabilities including multi-threaded encryption, encryption benchmarking, anti-analysis techniques, and self-deletion to evade detection. The group operates a public data leak site and has launched an underground forum called 'The Last Haven Board' to facilitate their activities. They target a wide range of file types, including SQL databases and network shares, increasing their impact on enterprise environments. Although no known exploits are currently reported in the wild, the threat is medium severity due to its cross-platform nature and complex attack techniques. European organizations, especially those with VMware ESXi and SMB-exposed systems, face significant risk. Denmark is specifically noted as affected, with other European countries likely at risk based on market penetration and strategic targets. Mitigation requires targeted patching of SMB vulnerabilities, network segmentation, monitoring for Cloudflared and SSHFS usage, and robust incident response plans. Join the discussion | AlienVault OTX General | 11/13/2025, 18:04:27 UTC Added: 11/13/2025, 20:05:17 UTC |
Showing 1 to 2 of 2 results