logo

DarkWatchman cybercrime malware returns on Russian networks

ID: a62d4e80-fab5-57f5-a1d5-86867443adab

STIX ID: report--a62d4e80-fab5-57f5-a1d5-86867443adab

Feed Name: The Record from Recorded Future News

Threat Score
60/100

Date Published: 2025-04-30

Date Updated: 2026-05-01

...
...

Researchers observed the financially motivated actor Hive0117 conducting phishing campaigns against Russian companies in media, tourism, biotech, finance, energy and telecoms using modified DarkWatchman malware delivered via password-protected malicious archives; the malware can log keystrokes, harvest data and deploy further payloads, though it is unclear whether recent attacks resulted in successful compromise or financial loss.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.