Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
ID: f085fa73-3a93-5a9e-8a43-8c7e7b8e953a
STIX ID: report--f085fa73-3a93-5a9e-8a43-8c7e7b8e953a
Feed Name: The Hacker News
A previously undocumented, likely Russian-affiliated threat actor is targeting Ukrainian defense, government, energy, aerospace, and humanitarian organizations using phishing lures (often LLM-generated) that point to Google Drive-hosted RAR archives containing CANFAIL — an obfuscated JavaScript that launches a PowerShell memory-only dropper and displays a fake error. Google GTIG links this activity to the PhantomCaptcha campaign and notes the group's evolving capabilities via LLMs for reconnaissance, social-engineering lure creation, and C2 setup, posing a significant risk to critical infrastructure and aid organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
