logo

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs

ID: f085fa73-3a93-5a9e-8a43-8c7e7b8e953a

STIX ID: report--f085fa73-3a93-5a9e-8a43-8c7e7b8e953a

Feed Name: The Hacker News

Threat Score
85/100

Date Published: 2026-02-13

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A previously undocumented, likely Russian-affiliated threat actor is targeting Ukrainian defense, government, energy, aerospace, and humanitarian organizations using phishing lures (often LLM-generated) that point to Google Drive-hosted RAR archives containing CANFAIL — an obfuscated JavaScript that launches a PowerShell memory-only dropper and displays a fake error. Google GTIG links this activity to the PhantomCaptcha campaign and notes the group's evolving capabilities via LLMs for reconnaissance, social-engineering lure creation, and C2 setup, posing a significant risk to critical infrastructure and aid organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.