logo

Unknown hacker group targeted Russian maritime universities, diplomats for nearly two years

ID: c9756ca0-bc95-5de8-8341-6701ae5ea6e0

STIX ID: report--c9756ca0-bc95-5de8-8341-6701ae5ea6e0

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2026-05-31

Date Updated: 2026-06-01

...
...

Kaspersky discovered a previously undetected, multi-year hacking campaign targeting Russian maritime universities, energy companies, diplomatic missions, government agencies and financial institutions. The actors used phishing ZIP attachments containing a malicious Excel configuration file to execute code and deployed a publicly available post-exploitation framework called Ravage; activity featured long dormant periods and a renewed wave beginning in January. Kaspersky did not attribute the campaign or describe observed post-compromise objectives or the total number of affected organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.