logo

Beyond Ukraine: Mercenary Akula Spearphishing Hits European Finance with Russian Remote Admin Tools

ID: fd70e3dd-b336-56f4-baff-6929b07fcb96

STIX ID: report--fd70e3dd-b336-56f4-baff-6929b07fcb96

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-27

Date Updated: 2026-04-23

Author: Ddos

...
...

On 2026-02-09 BlueVoyant identified a targeted spearphishing campaign attributed to Mercenary Akula against a European financial institution: the attackers used a spoofed Ukrainian judicial email and a Pixeldrain-hosted ZIP→RAR→passworded 7z chain (password provided in a text file) culminating in a double-extension executable that deployed an MSI installer for the Remote Manipulator System (RMS). The report highlights this living-off-the-land tactic, region-specific lures, and recommends increased user awareness, stricter filtering for complex archives, and application control to block unauthorized remote access tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.