logo

Cybercriminals target accountants to drain Russian firms’ bank accounts

ID: e8c4ff23-4106-5bb7-b9db-4f2a58a4774c

STIX ID: report--e8c4ff23-4106-5bb7-b9db-4f2a58a4774c

Feed Name: The Record from Recorded Future News

Threat Score
75/100

Date Published: 2026-04-08

Date Updated: 2026-05-01

...
...

Hive0117 conducted a large phishing campaign in Feb–Mar 2026 targeting accountants at over 3,000 Russian organizations to deliver DarkWatchman RAT via password‑protected archives; compromised machines were used to create fraudulent payroll payment orders that routed funds to attacker-controlled accounts, resulting in confirmed thefts (the largest >14M rubles). The campaign leveraged likely-compromised legitimate senders and tailored messages to finance staff, allowing attackers to bypass anti-fraud controls and move laterally within victim networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.