logo

Batavia spyware steals data from Russian organizations

ID: c5050016-f0fb-5fd7-b5fa-4beafaf60314

STIX ID: report--c5050016-f0fb-5fd7-b5fa-4beafaf60314

Feed Name: Securelist by Kaspersky

Threat Score
70/100

Date Published: 2025-07-07

Date Updated: 2026-04-29

Author: Kaspersky

...
...

The report details the Batavia spyware campaign (active since July 2024) that targets Russian industrial organizations via contract-themed phishing links which deliver an encrypted .vbe downloader; the campaign progresses through WebView.exe and javav.exe to establish persistence, perform UAC bypass, harvest documents, system logs and screenshots, and exfiltrate data to C2 domains (oblast-ru.com, ru-exchange.com); the report includes technical analysis and IOCs (three file hashes and C2 domains).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.