Cybercriminals target accountants to drain Russian firms’ bank accounts
ID: e8c4ff23-4106-5bb7-b9db-4f2a58a4774c
STIX ID: report--e8c4ff23-4106-5bb7-b9db-4f2a58a4774c
Feed Name: The Record from Recorded Future News
Hive0117 conducted a large phishing campaign in Feb–Mar 2026 targeting accountants at over 3,000 Russian organizations to deliver DarkWatchman RAT via password‑protected archives; compromised machines were used to create fraudulent payroll payment orders that routed funds to attacker-controlled accounts, resulting in confirmed thefts (the largest >14M rubles). The campaign leveraged likely-compromised legitimate senders and tailored messages to finance staff, allowing attackers to bypass anti-fraud controls and move laterally within victim networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
