logo

New Punishing Owl Hacker Group Targeting Networks of Russian Government Security Agency

ID: 480cf6ac-527c-59eb-93c9-ada5705f1762

STIX ID: report--480cf6ac-527c-59eb-93c9-ada5705f1762

Feed Name: cybersecurityNews.com

Threat Score
72/100

Date Published: 2026-02-02

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

Punishing Owl, a newly emerged hacktivist group, breached a Russian government security agency in December 2025, published stolen internal documents via a data leak site and a Mega.nz repository, and redirected victim traffic by creating subdomains and modifying DNS records to point to a Brazilian server hosting the files and a manifesto. The group also conducted business email compromise against partners using mail services hosted on attacker infrastructure, employed fake TLS certificates and IMAP/SMTP for operations, and deployed a ZipWhisper PowerShell-based infostealer delivered via LNK-in-ZIP phishing that harvested browser credentials and uploaded archives to a command-and-control server (bloggoversikten.com).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.