Suspected Russian hackers deploy CANFAIL malware against Ukraine
ID: 28697c99-1142-5ebc-926b-630fbda3f3e0
STIX ID: report--28697c99-1142-5ebc-926b-630fbda3f3e0
Feed Name: Security Affairs
Google Threat Intelligence Group identified a suspected Russia-linked APT conducting phishing campaigns against Ukrainian defense, government, energy, aerospace, and humanitarian organizations using CANFAIL — obfuscated JavaScript that spawns a PowerShell memory-only dropper — often delivered via Google Drive links and RAR archives disguised with double extensions; the actor leverages LLMs to craft lures and perform reconnaissance and has probed neighboring countries, with related activity noted by other labs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
