New Punishing Owl Hacker Group Targeting Networks of Russian Government Security Agency
ID: 480cf6ac-527c-59eb-93c9-ada5705f1762
STIX ID: report--480cf6ac-527c-59eb-93c9-ada5705f1762
Feed Name: cybersecurityNews.com
Punishing Owl, a newly emerged hacktivist group, breached a Russian government security agency in December 2025, published stolen internal documents via a data leak site and a Mega.nz repository, and redirected victim traffic by creating subdomains and modifying DNS records to point to a Brazilian server hosting the files and a manifesto. The group also conducted business email compromise against partners using mail services hosted on attacker infrastructure, employed fake TLS certificates and IMAP/SMTP for operations, and deployed a ZipWhisper PowerShell-based infostealer delivered via LNK-in-ZIP phishing that harvested browser credentials and uploaded archives to a command-and-control server (bloggoversikten.com).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
