logo

RST TI Report Digest: 01 Dec 2025

ID: 6746c78c-b675-5a65-80d9-8b4d607e145e

STIX ID: report--6746c78c-b675-5a65-80d9-8b4d607e145e

Feed Name: RST Cloud Blog

Threat Score
80/100

Date Published: 2025-12-01

Date Updated: 2026-04-29

Author: RST Cloud

...
...

**Executive summary:** F6 Threat Intelligence analyzed VasyGrek’s August–November 2025 activity and found a sustained campaign using advanced phishing and staged malware (a.exe loading a.dll) that culminated on 2025-11-13 with deployment of the PureHVNC RAT, which was executed stealthily via the legitimate RegAsm.exe process; the report includes extensive IOCs (IPs, domains, URLs, and many SHA1 hashes) tied to the actor’s operations in Russia.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.