Batavia spyware steals data from Russian organizations
ID: c5050016-f0fb-5fd7-b5fa-4beafaf60314
STIX ID: report--c5050016-f0fb-5fd7-b5fa-4beafaf60314
Feed Name: Securelist by Kaspersky
The report details the Batavia spyware campaign (active since July 2024) that targets Russian industrial organizations via contract-themed phishing links which deliver an encrypted .vbe downloader; the campaign progresses through WebView.exe and javav.exe to establish persistence, perform UAC bypass, harvest documents, system logs and screenshots, and exfiltrate data to C2 domains (oblast-ru.com, ru-exchange.com); the report includes technical analysis and IOCs (three file hashes and C2 domains).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
