logo

Exposing the Deception: Russian EFF Impersonators Behind Stealc & Pyramid C2

ID: 73b497f6-92ab-52a0-bf8e-6f450e3c663d

STIX ID: report--73b497f6-92ab-52a0-bf8e-6f450e3c663d

Feed Name: Hunt.io Blog

Threat Score
70/100

Date Published: 2026-02-16

Date Updated: 2026-04-28

...
...

The report documents a financially motivated campaign targeting Albion Online players by impersonating the Electronic Frontier Foundation, hosting decoy PDFs in an exposed open directory and delivering a PowerShell-based loader that drops a Python payload (Stealc infostealer and Pyramid C2 clients); investigators recovered multiple C2 IPs, shared SSH-key infrastructure linking additional hosts, forum reports of phishing, and a collection of file hashes and network observables useful for detection and blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.