RST TI Report Digest: 08 Jun 2026
ID: ec2f3915-798d-5f87-97be-d84b53f698c1
STIX ID: report--ec2f3915-798d-5f87-97be-d84b53f698c1
Feed Name: RST Cloud Blog
Threat Score
SiribClone is a cyber espionage group active since at least late 2025 targeting Russian military personnel with social engineering and phishing campaigns to steal Telegram credentials, two-factor codes, and other sensitive data; investigators found custom malware (SiribGrabber) and spyware (SafeLoveStealer), multiple C2 servers, phishing sites, and a long list of IOCs (IPs, domains, URLs, hashes) for detection and remediation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
