logo

Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware

ID: d09b5e38-a6ff-5fae-8e6c-130c9cd7cc4c

STIX ID: report--d09b5e38-a6ff-5fae-8e6c-130c9cd7cc4c

Feed Name: HackRead

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Deeba Ahmed

...
...

Operation HumanitarianBait is an active Python-based spyware campaign targeting Russian speakers by using phishing RAR attachments containing malicious LNK files that launch an in-memory, fileless payload hosted via GitHub Releases; the implant exfiltrates browser and Telegram credentials, scans for crypto keys, logs keystrokes and screenshots, installs remote-access tools, and persists via a Windows Scheduled Task while communicating with C2 infrastructure (e.g., 159.198.41.140) hosted on Namecheap.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.