logo

Suspected Russian hackers deploy CANFAIL malware against Ukraine

ID: 28697c99-1142-5ebc-926b-630fbda3f3e0

STIX ID: report--28697c99-1142-5ebc-926b-630fbda3f3e0

Feed Name: Security Affairs

Threat Score
85/100

Date Published: 2026-02-14

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Google Threat Intelligence Group identified a suspected Russia-linked APT conducting phishing campaigns against Ukrainian defense, government, energy, aerospace, and humanitarian organizations using CANFAIL — obfuscated JavaScript that spawns a PowerShell memory-only dropper — often delivered via Google Drive links and RAR archives disguised with double extensions; the actor leverages LLMs to craft lures and perform reconnaissance and has probed neighboring countries, with related activity noted by other labs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.