logo

Amnesia RAT deployed in multi-stage phishing attacks against Russian users

ID: 4761dda9-7f22-5999-899b-f0c0c34b4b41

STIX ID: report--4761dda9-7f22-5999-899b-f0c0c34b4b41

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-01-27

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

FortiGuard Labs uncovered a multi-stage phishing campaign targeting Russian users that uses fake business documents to trick victims into running a PowerShell loader (kira.ps1) which downloads additional obfuscated scripts from GitHub/Dropbox; the attack culminates in deployment of Amnesia RAT for broad data theft and persistence and Hakuna Matata ransomware/WinLocker for encryption and extortion, while disabling Microsoft Defender and exfiltrating data via Telegram and cloud file hosts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.