Visualização de leitura

2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators

2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm.

Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU

More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international media consortium, and the picture they describe is not a conventional cybersecurity program. The files span academic and administrative records through 2025.

“Recently leaked records show that Bauman Moscow State Technical University’s Department No. 4 operated as a long-term training pipeline for Russian military intelligence and cyber operations.” reads the report published by DomainTools. “The department served several elements of the Russian General Staff and trained roughly 250 career and reserve students across three specialties: special intelligence (“Служба специальной разведки”), operational information-technical effects (“Применение сил и средств информационно-технического воздействия и защиты от информационно-технического воздействия”), and information-technology protection (”3ащита информационных технологий”). “

Department No. 4, also called “Special Training,” operated inside Bauman’s Military Training Center and doesn’t appear anywhere on the university’s public organizational chart. The GRU’s talent pipeline tends not to announce itself.

The investigation was carried out by a group of media outlets including The Insider, The Guardian, Le Monde, Der Spiegel, Delfi, VSquare, and FRONTSTORY.PL. DomainTools researchers also analyzed the leaked files independently. A DarkForums user known as “Losyash” may have shared the data, but it has not been confirmed that the account originally obtained the records.

The department trained students in three military specialties. These covered special intelligence, information and cyber operations, and the protection of IT systems. In practice, the courses included espionage, offensive cyber operations, electronic reconnaissance, secure systems, and influence operations.

Around 250 career and reserve students went through the program over six academic years. Researchers estimate that 10 to 15 students each year were selected for GRU-related assignments before graduating.

“Technical protection training covered cryptography and steganography, as well as code analysis and intrusion detection. Students were also trained in hardware inspection, the discovery of physical implants, and the identification of undocumented device functions. These subjects point to possible assignments in technical counterintelligence and supply chain security, as well as firmware analysis and embedded system inspection. Other likely functions include secure procurement and the protection of specialized military platforms.” continues the report. “The files also reveal an underreported malware-analysis and cyber threat intelligence program.”

One advanced practical assignment required the creation of a social-media video built around what the course materials called “manipulation, pressure, and hidden propaganda.” This counted as coursework.

Course materials defined “information-technical weapons” as tools and methods designed to alter, destroy, copy, block, or manipulate information. Red-team and blue-team functions were treated as a single discipline, not separate tracks, which mirrors how Russian military doctrine actually deploys cyber operators.

The personnel links are what make this more than a training curiosity. The leaked records identify Major General Viktor Netyksho as involved in Department No. 4’s oversight. Netyksho was the former commander of Military Unit 26165, the GRU formation publicly associated with APT28, also tracked as Fancy Bear, Sofacy, and STRONTIUM. He was among the 12 GRU officers indicted by the United States in 2018 for interference in the 2016 presidential election.

Reporting identified graduates assigned to GRU Military Unit 26165 (associated with APT28) and Military Unit 74455 (associated with Sandworm), and linked senior officers, including former Unit 26165 commander Viktor Netyksho, to student oversight.” continues the report. “The data also connected senior GRU officers to the supervision and evaluation of Bauman students. Viktor Netyksho, the former commander of Unit 26165 and the 85th Main Special Service Center, is part of the department’s teaching and oversight structure.”

The reporting also identifies Aleksei Kondrashov, a 2024 Department No. 4 graduate, as linked to Military Unit 74455: the GRU’s Main Center for Special Technologies, known publicly as Sandworm, or APT44. That unit has been associated with the 2017 NotPetya attack and ongoing destructive operations against Ukraine. DomainTools also connected graduates and senior staff to Military Unit 29155, a GRU formation linked to sabotage and assassination operations in Europe.

A necessary precision: the reports establish unit placements, not individual operational involvement. A documented assignment to Military Unit 74455 doesn’t establish that a specific person participated in a specific attack. That distinction matters for both attribution work and legal proceedings.

What the leak does establish is the factory behind the names. APT28 and Sandworm are the threat groups that security teams track, attribute, and brief about. Department No. 4 is where some of the people running those operations were systematically trained, assessed, and selected.

For defenders, DomainTools summarizes the implication precisely: Russian operations should be tracked as a combined threat in which espionage, destructive attacks, military reconnaissance, technical surveillance, and influence campaigns draw on the same personnel pipelines and the same underlying doctrine. The Bauman material makes that pipeline visible for the first time at this level of institutional detail.

“The documents show that Department No. 4 is a small part of a larger long-term military training system, not a single hacking unit. The program prepared personnel for espionage and offensive cyber operations within a larger Russian technical university system.” concludes the report. “Its doctrine treated cyber warfare as more than network intrusion. Students were taught not only adversarial cyber warfare, but also a larger holistic doctrine of cyber war using both defense and attack to be better able to carry out successful campaigns.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Russia)

Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement.

The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups.

It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.

For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine.

The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.

Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations

BlueDelta (APT28) uses webhook.site and Microsoft Edge to hide HOOKEDGE espionage traffic targeting European governments.

Recorded Future’s Insikt Group documented a campaign by BlueDelta, the Russian GRU-linked group that overlaps with the group APT28, running an entire espionage operation against European government targets using webhook.site, a service built for developers to test HTTP requests, as its command-and-control backbone.

The campaign ran from late September 2025 through early April 2026, targeting government and diplomatic organizations in Romania, Spain, and Türkiye.

“The campaigns delivered a lightweight Windows batch-script backdoor, dubbed “HOOKEDGE,” via macro-enabled Microsoft Word documents using diplomatic-themed lures, including material impersonating Spain’s Ministry of the Presidency, Justice and Relations with the Cortes, created shortly after a September 2025 meeting between Spanish and Moldovan officials.” states the report by Insikt Group.

“Insikt Group assesses with moderate confidence that this activity was conducted by BlueDelta (which overlaps with APT28, Fancy Bear, and Forest Blizzard), a Russian state-sponsored threat group attributed to the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).”

The attackers used a fairly old-school trick: macro-enabled Word documents. One of them looked like a real meeting agenda from Spain’s Ministry of the Presidency and appeared shortly after an actual meeting between Spanish and Moldovan officials. The timing was interesting because it came just before Moldova’s September 2025 parliamentary elections. The document looked credible enough to make the phishing attempt believable.

The backdoor, called HOOKEDGE, is surprisingly simple. It uses a Windows batch script and relies on two webhooks. One receives commands, while the other sends the stolen data back to the attackers. Every 30 minutes, a scheduled task downloads a command file through Microsoft Edge, runs it and sends the results to another endpoint. The malware uses Edge to make the traffic look like normal web activity, making it harder for security tools to spot.

That reliance on a real browser for both tasking and exfiltration is the cleverest part of the whole design.

“A notable aspect of HOOKEDGE is its use of msedge.exe for both tasking and exfiltration. By generating network traffic through a legitimate web browser rather than a commonly abused LotL binary (LOLBin) or a custom binary, the malware blends its communications with normal enterprise browsing activity.” continues the report.

Recorded Future explains, and that’s really the entire evasion strategy in one sentence: don’t build something exotic, just make your traffic look exactly like an employee checking a website.

BlueDelta didn’t build HOOKEDGE from scratch either. It shares deep code and structural overlap with HEADLACE, a backdoor the same group used years earlier, right down to identical JavaScript variable names and the same base64 encoding scheme for automated downloads.

“HOOKEDGE’s code and structural design have significant overlap with HEADLACE, a backdoor used by BlueDelta in previous campaigns.” states the report.

Recorded Future assesses with moderate confidence that HOOKEDGE is a direct evolutionary successor, maintained by the same operators rather than a fresh tool built by a different team, which fits BlueDelta’s long-documented habit of refining working tradecraft instead of reinventing it.

The operation also included a triage mechanism worth understanding on its own. Once a victim showed signs of being worth deeper attention, active communication with the initial webhook endpoints, BlueDelta deployed a second HOOKEDGE payload configured to check in every five minutes instead of thirty, giving operators much faster interactive control over higher-value targets. That two-tier setup also solved a practical infrastructure problem: webhook.site’s free tier caps out at 100 requests per endpoint, so spreading routine and high-priority tasking across separate endpoints kept any single one from getting exhausted mid-operation.

BlueDelta kept tuning the operation continuously rather than treating it as a finished product. Beaconing intervals stretched from 30 minutes to 61, deliberately timed to slip past sandbox environments that typically only watch a sample’s behavior for an hour. The group added canary tracking pixels named things like mailopened.jpg and docopened.jpg to monitor exactly when a phishing email got opened versus when the document itself got opened versus when macros actually executed, essentially building analytics for their own phishing funnel.

“The malicious document also contains a hidden image referencing a remote webhook URL: hxxp://webhook[.]site/62114596-33f5-47fb-9012-0223529e5a13/docopened[.]jpg. This serves as a document-open “canary,” alerting BlueDelta operators when a victim opens the lure. Later variants used the filename doc.jpg in place of docopened.jpg.” states Insik. “Insikt Group also identified webhooks using the filename mailopened.jpg, indicating that BlueDelta likely used a similar canary mechanism to monitor when recipients opened phishing emails, providing operators with visibility into campaign delivery success before any payload execution.”

That kind of detailed tracking of what victims do would look very familiar to a marketing team. The difference is that here the targets are victims, not customers.

For defenders, the useful indicators are quite clear. Block macros in documents downloaded from the internet, monitor scheduled tasks that launch scripts from user-writable folders, and flag Microsoft Edge running in headless mode or making automated connections to file-sharing and webhook services that the organization does not normally use. You don’t need sophisticated tools to spot these behaviors. Even a well-configured monitoring system should be able to detect them early. The worrying part is that a persistent, state-backed group can still rely on a small set of behaviors that defenders can identify and block.

For defenders, the actionable pieces here are concrete rather than abstract. Block macro execution from documents that arrived over the internet, watch for scheduled tasks spawning script interpreters from user-writable folders, and specifically flag Microsoft Edge running in headless mode or making automated requests to file-hosting and webhook services your organization doesn’t actually use for anything legitimate. None of this requires exotic tooling to catch, which is oddly reassuring: a threat group this persistent and state-backed is still, at its core, relying on the same handful of detectable behaviors that a properly configured monitoring setup would catch on day one.

“BlueDelta is likely to continue conducting initial access campaigns against European government and diplomatic organizations in support of Russian intelligence collection. Given the enduring strategic importance of European governance, NATO-related affairs, and diplomatic engagement with former Soviet republics, the intelligence requirements driving this activity are unlikely to diminish in the near term.” concludes the report.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, BlueDelta)

OpenAI banned Russian ChatGPT accounts backing covert influence operation

OpenAI banned Russian ChatGPT accounts backing a fake think tank, IBI, that used AI posts and a fake “sovereignty” index to push pro‑Russia narratives.

OpenAI says it has banned a cluster of ChatGPT accounts that likely originated in Russia and were used to support a covert influence operation. The campaign promoted an organisation called the International Burke Institute, or IBI, a supposed expert community that claimed to be based in Israel.

The operation did not rely on dramatic deepfakes or a viral bot army. It used a more familiar method: build something that looks credible, fill it with enough content to seem legitimate, then use social media to push people toward it. Credibility is often cheaper to fake than to earn.

OpenAI says the operators prompted ChatGPT in Russian to generate comments and posts, mostly in English, for X, Facebook, LinkedIn, Telegram and Substack. They specifically asked the model to avoid linguistic signals that might reveal a Russian origin, and used VPNs to bypass OpenAI’s restriction on access from Russia.

“We banned a cluster of ChatGPT accounts that very likely originated in Russia. The operators prompted in Russian to generate social media comments that were posted on Substack, Telegram, X, Facebook and LinkedIn.” reads the report published by OpenAI, “Most of the comments they generated were in English, and the operators instructe. ChatGPT to hide any linguistic clues that they were Russian. As we do not allow access to our models from Russia, they used VPNs to access our platform.”

The social media content promoted IBI articles or urged readers to follow IBI-linked channels. Some posts came from accounts bearing the institute’s name and logo, while others appeared to come from ordinary users whose main activity was sharing the same material.

The website behind the brand was registered in February 2025 and presented itself as an Israel-based community of international experts. It claimed links to well-known names such as Francis Fukuyama and Noam Chomsky, but OpenAI’s review found that 34 of 36 sampled articles published under expert profiles had been copied from elsewhere online.

“Some of these articles were years old; others were attributed to the wrong authors. For example, one article on the China-Pakistan Economic Corridor appears to have been copied from a Cambridge University Press original, but incorrectly attributed to a professor at the University of Nottingham whose expertise is in South Asian politics.” continues the report.

This was not a case of ChatGPT writing every false article on the site. OpenAI says the website content itself was not generated by its models, and some material appeared to have been written by a Slavic-language speaker and machine-translated. The AI’s role was narrower but still useful: it helped create the promotional layer that sent people toward the site and made the operation appear more active and organic.

“What began as an investigation into AI-generated social media posts led us to a much broader influence operation, built around a website containing copied and misattributed academic work, a “sovereignty” index that cast Russia in a favourable light, and efforts to disguise the operators’ Russian origins.” states OpenAI. “Although the campaign appears to have reached relatively small audiences, its elaborate construction distinguishes it from other Russia-linked⁠(opens in a new window) influence⁠(opens in a new window) operations⁠(opens in a new window) we have disrupted⁠(opens in a new window) since the start of the war in Ukraine.”

The centrepiece was the so-called Sovereignty Index, also called the Burke Index. It ranked countries across political, economic, technological, information, cultural, cognitive and military dimensions, and consistently gave Russia a favourable place while criticising Western states, especially France, Germany, the European Union and the United States. openai

A made-up index can be effective because numbers carry authority even when the method is vague, selective or impossible to audit. Add charts, expert profiles, academic-looking articles and a professional website, and a claim can travel much further than a Telegram post from an anonymous account.

OpenAI found one Telegram channel, “Lahme Ente,” that published German-language posts attacking Ukraine, the EU and the German government while calling for closer ties with Russia. Another operator used ChatGPT to create logos for channels focused on Germany, France, Poland, Türkiye and the United States, then repeatedly asked for Russian-language summaries of their activity.

“As well as generating content about IBI, one of the operators generated German-language posts that were posted on a Telegram channel called “Lahme Ente” (“lame duck”). These posts routinely criticized Ukraine, the EU and the German government, and advocated for better relations with Russia.” continues the report. “A second operator, alongside their IBI-related content, generated logos for a dozen Telegram channels (including Lahme Ente) focused on Germany, the USA, France, Poland and Türkiye. “

One American-facing channel called “American Observer” included awkward English that suggested it was not run by a native speaker. The operators were trying to hide their origin, but language remains a stubborn problem: a VPN can change an IP address, not always a sentence.

The campaign’s immediate reach appears limited. OpenAI says most social posts received few views and the official IBI accounts had low subscriber counts, although its Telegram channels reportedly attracted around 10,000 to 20,000 followers each. Using the Brookings Breakout Scale, OpenAI rated the effort at the lower end of Category Three: activity across multiple platforms with some signs of reaching genuine audiences.

That does not make it irrelevant. Influence operations are often built for scale, reuse and timing rather than instant virality. A network with a website, a recognisable brand, social accounts, apparent experts and ready-made narratives can remain quiet until a political event, election, protest or crisis gives it an opening.

This case also shows what AI changes and what it does not. It does not eliminate the need for operators, infrastructure, stolen material, audience research or political intent. It makes routine tasks cheaper: drafting posts, translating them, changing tone, generating replies, creating branding and monitoring channels at a pace that a small team can sustain.

“The significance of the operation lies less in the audience it reached, however, than in the infrastructure it had built. While the actors only used ChatGPT to produce isolated promotional posts, those posts pointed to an otherwise credible-appearing institution, complete with purported experts, republished academic work and a purported proprietary risk index.” concludes the report. “This illustrates how influence actors can use AI as a supporting tool within a broader effort to manufacture authority, obscure the source of favored narratives, and establish assets that could be scaled over time. It also illustrates how their supporting use of AI can lead to the broader operation being exposed.”

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, OpenAI)

Tracking a Sanctioned Russian Vessel’s West African Odyssey

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat  was an unusual set of movements and behaviours.

Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March. 

It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea. 

The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.

It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.

Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms. 

Tracking the Patria

Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes. 

At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.

Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship

This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.

For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.

MapLibre | Protomaps© OpenStreetMap contributors

Port of Olga, Russia

AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.

Credit: Planet Labs PBC.

Lagos Anchorage, Nigeria

AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.

A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.

Credit: Contains modified Copernicus Sentinel data 2026.

Bata Anchorage, Equatorial Guinea

AIS data and satellite imagery indicate Patria stayed off the coast of Equatorial Guinea for several days.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data and satellite imagery indicate Patria loaded at the Port of Owendo in Libreville after spending a few days off the coast.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.

Port of Douala, Cameroon

AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.

Credit: Planet Labs PBC.

A third trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.

A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.

Lagos Anchorage, Nigeria

AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.

Credit: Planet Labs PBC.

Examining the Patria’s Draught

We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.

A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).

Draught is the depth of a ship below the waterline. 

In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.

The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports. 

Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.

Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.

“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.  


“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.” 

He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy. 

David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.

Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.

Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:

“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”

Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.

The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.

Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.

Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracking a Sanctioned Russian Vessel’s West African Odyssey appeared first on bellingcat.

Security Issues in the Korean & Global Financial Sector in July 2026

Statistics on Malware Distributed to the Financial Sector In Attack Stage 1, phishing (a technique that tricks users into opening malicious links or attachments) had the highest rate at 1.7, Down from 2.3 The previous month. In Attack Stage 2, Dropper/Downloader (a type that downloads additional malware) was the most prevalent at 1.7, Up from […]

Fake Conferences, OAuth and WhatsApp: Inside Russia’s New Espionage Tactics

Google tracks three Russia-linked espionage clusters using phishing and legitimate authentication tools to target researchers, diplomats and defense staff.

Google’s Threat Intelligence Group tracked three separate suspected Russia-linked cyber espionage clusters. All three focus on the same thing: abusing authentication features that are supposed to protect accounts to access them instead.

Threat actors target researchers, academics, government officials, think-tank analysts, and defense sector personnel across Europe and the United States. The three clusters are tracked as UNC6293, UNC7005, and UNC5976, and while they operate differently and with different tools, Google published them together for a reason.

“These clusters engage in persistent, adaptive phishing campaigns, using sophisticated social engineering tactics to compromise personal accounts across multiple platforms.” reads the report published by GTIG. “Because these operations abuse legitimate authentication flows which may not immediately seem like phishing attempts to users, GTIG is raising awareness about these social engineering campaigns targeting individuals so that targets can more readily recognize malicious outreach.”

UNC6293 is the oldest of the three and the most precisely attributed. Google assesses with moderate confidence that it’s a sub-cluster of ICE RELIC, the group also tracked as APT29, responsible for initial access operations.

Its operations are narrow by design: typically fewer than five targets at a time, with themes built around diplomatic events and upcoming conferences. Since it was first documented in June 2025, UNC6293 has consistently impersonated US State Department officials to run app password phishing. The technique is simple but effective. The attacker convinces a target to set a specific app password on their account, one that the attacker already knows, and then uses it to log in without triggering two-factor authentication.

By October 2025, UNC6293 was still reusing screenshots from its June phishing lures, including the ms.state.gov reference, while only changing the surrounding text. By June 2026, the group had added OAuth phishing. After logging in to a legitimate service, victims were asked to share a URL or “verification code,” allowing attackers to obtain valid access tokens. The trick works because the login itself is legitimate, while the attackers hide the malicious step elsewhere.

UNC7005, tracked by Microsoft as STORM-2945, is a related but separate cluster first identified in February 2026. Google assesses it’s also connected to ICE RELIC, but notes it operates with lower technical sophistication and worse operational security than UNC6293. It compensates with a wider toolkit. UNC7005 runs app password phishing, device code phishing against both Microsoft and WhatsApp, malware distribution, and OAuth phishing operations, sometimes in the same month.

“UNC7005 also conducts device code phishing operations for both Microsoft and WhatsApp accounts.” continues the report. “The themes of these phishing waves often involve invitations for calls with individuals from notable organizations related to the target’s field or, most recently, invitations to diplomatic events and conferences. “

The GLOBSEC conference spoof is a useful illustration of how UNC7005 works. The actor built a landing page mimicking an invitation to the legitimate GLOBSEC forum in May 2026, collected detailed registration information from targets including, not for the first time in ICE RELIC-linked operations, a wine selection for a fictional dinner, and then presented a Microsoft device code for the target to enter. The registration form still contained a reference to “Embassy security policy” rather than GLOBSEC, a leftover from the previous lure template that the actor hadn’t cleaned up. When Google flagged the page quickly, UNC7005 revised the template within days, citing “technical difficulties” to explain the change to anyone still watching.

Russia Linked APT

UNC7005 also used WhatsApp phishing pages to trick victims into linking their accounts to an attacker-controlled device. The fake pages offered options such as joining a call, opening an encrypted chat or downloading a file. If victims chose the call option, malicious JavaScript asked for microphone and camera access, recorded them, and sent the footage to the attackers.

In late May 2026, UNC7005 ran a broader phishing wave targeting US-based academics, diplomats, and Russia researchers. The lure was a fake “Summit Companion App” to read a document supporting Ukraine.

“In May and June 2026, UNC7005 conducted social engineering operations spoofing WhatsApp. The phishing pages distributed by the attacker lure targets into linking their WhatsApp accounts with an attacker controlled device in order to join a secure WhatsApp call, chat, or document share.” states the report. “The attacker also attempts multiple other methods of compromise after the device is linked.”

Windows users who downloaded it received VIDAR, an off-the-shelf infostealer sold as a service that pulls saved credentials, cookies, and payment data from browsers. Mac users received ATOMIC, also known as AtomicStealer, a macOS infostealer operating the same business model. Neither is custom tooling. The actor’s email address in this operation was nearly identical to one used by UNC6293 a year earlier.

The hospitality captive portal campaign, previously reported by Reliaquest and Microsoft and attributed to Midnight Blizzard, connects directly to UNC7005. Google traces the infrastructure back to April 2026: domains spoofing Microsoft authentication resources, which Google added to Safe Browsing blocklists as they appeared. By mid-July 2026, those same domains were receiving redirects from captive portals at hotels and conference centers. The IP resolution trail links the captive portal infrastructure to the GLOBSEC device code phishing operation and to ENGINELIGHT, a Go-based malware used in a separate limited UNC7005 operation in May 2026.

CHERRYPIE, also known as ChocoShell, is a PowerShell infostealer that adds another interesting detail. Google found comments and code references that appear consistent with AI-generated code, suggesting the attackers may be using an LLM to develop malware. The data it targets overlaps with the commercial infostealers already used by UNC7005, leading Google to suspect that CHERRYPIE could be a customized version of a malware-as-a-service tool.

UNC5976 is the third cluster and the most distinct. It focuses on military, aerospace, defense industrial base, and NGO targets, concentrating geographically on Ukraine and Armenia. Instead of residential proxies for post-compromise access, as UNC6293 and UNC7005 use, it runs dedicated infrastructure. Its OAuth phishing is more automated: the actor registers file-sharing-themed domains, creates Google Cloud projects behind them, and uses cloud-hosted scripts to collect authentication tokens from targets who log in through what looks like a Google sign-in prompt on a fake file-sharing page. Within three months of Google disrupting this infrastructure, UNC5976 had built at least twelve new domains and was already migrating toward non-Google hosting providers.

In April 2026, UNC5976 also distributed HEADRUSH, a malicious Excel plugin, through a domain impersonating a Ukrainian research institute, potentially targeting a Ukrainian aerospace and imaging company. HEADRUSH eventually leads to an HTA downloader, though Google wasn’t able to recover the full infection chain.

The defender challenge that runs through all three clusters is the same one Google names directly.

” The accounts these groups target are often personal, rather than corporate domain-joined accounts, creating a visibility gap for monitoring compromise from an organizational perspective. The likely use of encrypted messenger applications instead of email for initial outreach also presents a challenge to defenders hoping to track and remediate abuse.” concludes the report. “The combination of these tactics not only enables the attacker to conduct quick-turnaround exfiltration operations, but also presents opportunities for the attacker to further phish targets of interest from compromised, legitimate accounts. “

Security teams watching corporate email and endpoint telemetry won’t see the initial contact. By the time a compromised personal account starts being used to phish the target’s contacts, the original access event is already cold.

Google’s practical guidance for individuals: don’t set app passwords for anyone who asks, revoke existing ones you don’t recognize, check WhatsApp’s linked devices list, and treat any OAuth authorization prompt from an unsolicited message as suspicious regardless of how polished the surrounding page looks. High-risk individuals should consider Google’s Advanced Protection Program, which blocks app password creation entirely.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Russia)

Inside Operation CameraSwarm: How One Actor Took Over 14,000 Dahua Cameras

An exposed operator directory reveals how one actor compromised 14,000+ Dahua cameras across Ukraine and Russia, no password needed for most.

A researcher discovered an exposed directory containing the tools of an attacker who compromised more than 14,000 Dahua cameras between June 17 and July 22, 2026, mainly in Ukraine and Russia. Hunt.io reconstructed the operation, named Operation CameraSwarm, from the leaked files and telemetry.

The find started with a mistake. On 23 July, Hunt.io’s AttackCapture system crawled a server at 154.86[.]119.60 and pulled down 2,616 files across 234 subdirectories, 407 MB in total, from an HTTP directory the operator had left wide open. That single slip handed researchers the operator’s scanning engine, exploit chains, exfiltration bot, and a Windows stealer staged on the same box.

“This is the second Dahua-related camera compromise operation we’ve traced back to an exposed operator directory in as many weeks. Where last week’s investigation centered on a Russian-speaking operator running a purpose-built platform against 58 cameras, this one is a different scale entirely.” reads the report published by Hunt.io.

The brute-force engine alone reached over 12,300 unique addresses. A separate authentication-bypass chain, built around two 2021 Dahua vulnerabilities, planted a persistent backdoor account on 1,923 cameras, an account stored independently of the admin password that survives both a password change and, on most firmware, a factory reset. A third path skipped IP addresses entirely and reached 283 cameras purely by serial number, through Dahua’s own cloud relay.

That third path is the part worth sitting with. Most of those cameras were exposed online without authentication.

Dahua’s cloud relay lets any app reach a camera sitting behind NAT using nothing but its serial number, and authentication to that relay runs on credentials baked identically into every Dahua client ever shipped. The operator’s own code logs the result of probing this channel at scale: 89.4 percent of live serials returned an open, no-authentication channel. Nine out of ten cameras, reachable by anyone who could guess or harvest a serial number.

“The device never authenticates the connecting party. It authenticates the session, via a token the cloud issued before the device was contacted. Obtaining that token requires only the fixed SDK credentials shared by every legitimate Dahua application.” continues the report. “The only real barrier to reaching any camera through this path is knowing its serial number, precisely what the operator’s harvesting pipeline exists to produce at scale.”

Getting from the tunnel session to full admin access still requires valid credentials or an authentication bypass. However, the attacker’s own logs suggest that most exposed cameras did not need this final step.

There are also two important details about the reported CVEs. The tool links its persistent backdoor technique to CVE-2024-39943, but that CVE actually refers to a different command-injection flaw in Rejetto’s HTTP File Server. The technique is valid, but the CVE reference is wrong. Likewise, the relay abuse is not CVE-2025-31702, which Dahua describes as a narrower authenticated privilege-escalation flaw. Incorrect CVE references can send defenders looking for the wrong fix.

Hunt.io also found something that had nothing to do with cameras: a UPX-packed Windows binary, tagged as SalatStealer, staged on the same server alongside a PowerShell script that disables Windows Defender five different ways, including a Group Policy key built to survive reboots and Defender updates. The researchers treat it as a separate, unrelated capability riding along on shared infrastructure, not part of the camera campaign proper.

What stands out across the whole toolkit is that none of it was built from scratch. The brute-force engine, the bypass chain, the relay tooling, the recovery-code generator: each traces to a different public repository, credited (sometimes accurately) to at least six other developers. The operator assembled, patched, and rewrote, layering Russian comments over Spanish code in one component recovered in three separate stages of the same rewrite.

“The same toolkit also recovers stored device passwords outright, through a routine that derives its decryption key entirely from values the attacker already holds, device class prefix and serial number, so no device secret is needed. A residual Spanish comment in that code confirms it came from the same upstream source as the original brute-forcer.” states the report.a

The offline recovery-code generator is arguably the most consequential piece precisely because it doesn’t need a compromised device at all. Given a live serial number, it derives a code entirely offline that unlocks Dahua’s cloud-level account-recovery flow, no current credentials required. Removing a backdoor account doesn’t touch this. Only Dahua changing how the code is derived would.

For anyone running Dahua gear, or the OEM-rebranded lines built on the same backend (Amcrest, Lorex, Annke, Swann, among others), the practical checklist is short: check for a p2pwn account and remove it, disable P2P on any device where it isn’t actually needed, confirm firmware is patched against the 2021 bypass pair, and rotate every credential that camera ever held, since the exfiltration bot grabbed those too. None of that fixes the recovery-code problem. That one sits with the vendor.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)

New Zealand Targets Russian Cyber Actors With Fresh Sanctions

New Zealand Sanctions

New Zealand has announced a new round of sanctions against Russia, targeting 33 individuals and entities accused of supporting Moscow’s war against Ukraine. The latest New Zealand sanctions against Russia place particular focus on cyber actors, individuals linked to the forced relocation and re-education of Ukrainian children, and entities supporting Russia’s military-industrial complex. Foreign Minister Winston Peters said the package also targets individuals involved in creating and spreading anti-Ukraine propaganda, as well as actors from the Democratic People’s Republic of Korea (DPRK) and Iran providing support to Moscow. “Children should never be used as instruments of war,” Peters said, expressing concern over efforts to abduct and re-educate Ukrainian children through state-directed programmes.

New Zealand Sanctions Target Russian Cyber Actors

The latest Russia sanctions include several individuals previously accused by the United States and other Western governments of malicious cyber activity. Among them are Yuliya Pankratova and Denis Degtyarenko, members of the pro-Russian hacktivist group Cyber Army of Russia Reborn (CARR). The U.S. Treasury sanctioned both individuals in 2024 over alleged cyber operations targeting U.S. critical infrastructure. U.S. officials identified Pankratova, who uses the alias “YUliYA,” as the group’s leader, while Degtyarenko, known as “Dena,” was described as one of its primary hackers. American officials alleged that Degtyarenko was responsible for compromising an industrial control system at a U.S. energy company and had developed training materials for compromising supervisory control and data acquisition (SCADA) systems. Pankratova has also allegedly been associated with Z-Pentest, another pro-Russian hacking group accused of targeting critical infrastructure. New Zealand has also sanctioned Aleksandr Volosovik, known online as “Yalishanda.” U.S. prosecutors have accused him of helping operate Media Land, a Russian bulletproof hosting provider allegedly used by cybercriminals to target organizations including hospitals, schools and banks. In July, the U.S. Justice Department unsealed charges against Volosovik and two other Russian nationals, alleging activities that caused more than $62 million in losses to victims in the United States and other countries.

GRU-linked Official Among Sanctioned Individuals

Another individual included in the latest New Zealand sanctions against Russia is Andrey Averyanov, a senior Russian military intelligence officer who previously commanded GRU Unit 29155. Western governments have linked the unit to cyberattacks, sabotage and other covert operations. Its cyber division has been accused of targeting governments, defense organizations, think tanks and other entities in Ukraine and NATO countries. New Zealand had previously sanctioned members of the unit over alleged malicious cyber activity targeting Ukraine and other countries.

Russia Propaganda and Technology Entities Targeted

The new sanctions also target Russia’s Internet Development Institute (IRI), a Kremlin-backed organization that finances digital media and content promoting Russian state narratives. IRI director Alexey Goreslavsky has also been designated. The British government has previously said the institute was established by Russia’s presidential administration and received hundreds of millions of dollars in government funding. Its projects have included films and video games promoting narratives associated with the Kremlin. Russian information technology company LANIT has also been added to the sanctions list. The company has provided services to Russia’s Defense Ministry and sanctioned defense-industry companies, including state-owned conglomerate Rostec. LANIT had previously been sanctioned by the United States, Canada and Ukraine.

New Zealand Reaches 36th Russia Sanctions Round

The latest package represents New Zealand’s 36th round of Russia sanctions since the Russia Sanctions Act came into force in March 2022. New Zealand has now imposed sanctions on more than 2,000 Russian individuals, entities and vessels, alongside trade restrictions. The measures generally include asset freezes and travel bans and prohibit New Zealanders from making funds or other assets available to designated individuals and entities. Peters said cyber activity can have real-world consequences, noting that cyber actors are increasingly being used to gather intelligence, enable sanctions evasion and disrupt those opposing Russia’s aggression.

Smashing Security podcast #479: How a fake police officer nearly stole Graham’s cryptocurrency

Graham gets a phone call from the police. Well, someone who sounds convincingly like the police. There's just one small problem: what they really want is the 24-word seed key to Graham's cryptocurrency wallet. Meanwhile, if you've stayed in a hotel recently, the free Wi-Fi you connected to might have come with an unexpected extra: an all-you-can-eat buffet of "Captive Crunch" for a Russian intelligence-linked hacking group. And a group calling itself the "ExFilSquad" has walked off with 600,000 records of the UK's teachers and head teachers from the Department for Education — sending an unusually polite ransom demand. All this and more in episode 479 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers.

Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS and HTTP traffic on captive portal networks at hotels, conference centers, and shared venues worldwide to redirect guests toward malware and credential theft operations. If you connected to hotel Wi-Fi while traveling in the past few months, this report is worth reading carefully.

“Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945 manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure.” reads the report published by Microsoft. “To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries. ReliaQuest has identified this activity not only at hotels, but also conference centers and other shared venues, and assesses that the goal of this activity is to access the accounts of corporate travelers.”

Russian Hackers Hijack Hotel Wi-Fi

That last point matters: the shared infrastructure patterns suggest this may not be a series of individual venue compromises but rather access to something shared across portions of the captive portal ecosystem. Microsoft hasn’t named any provider.

The malware delivered through these networks is CornFlake, a full-featured Windows remote access trojan written in Go.

“CornFlake registers as a Windows service named svchost32 with the display name “Cloud Sync Service and description “Synchronizes files with the cloud storage provider”, deliberately mimicking the legitimate svchost.exe process.” continues the report. “It establishes redundant persistence mechanisms: Windows service registrations, Registry Run keys, named scheduled tasks, and a persistence watchdog routine that runs continuously to restore any persistence mechanism that is removed by defenders or endpoint protection.”

CornFlake establishes an encrypted C2 channel using ECDH P-256 key exchange and supports dynamic reconfiguration without redeployment. Once installed, the RAT can log keystrokes, monitor the clipboard, capture screenshots, audio and webcam feeds, steal browser credentials, exfiltrate files, monitor USB devices, collect detailed system information, and execute remote commands. It also exposes a local HTTP API, allowing companion malware such as ChocoShell to reuse its secure C2 channel for file theft, configuration updates, and connectivity checks.

“For command and control (C2), CornFlake performs an Elliptic Curve Diffie-Hellman (ECDH) P-256 ephemeral key exchange with the C2 server, derives a session key via SHA-256, and communicates over a custom JSON protocol framed within the encrypted channel.” states the report. “This provides an encrypted channel to the C2 server, with each C2 session using a unique ephemeral key, making decryption of captured traffic impossible without the session-specific private key. “

Each C2 session uses a unique ephemeral key, which means captured traffic can’t be decrypted without that session’s private key. The malware also supports a runtime configuration file that lets the attacker reconfigure C2 servers and targeting without redeploying the implant.

CornFlake is delivered via ClickFix-style pages that impersonate Windows Update screens, Google verification pages, DirectX installers, browser update prompts, and disk optimization utilities — whatever looks most plausible for the venue. The victim still has to execute the payload, but the captive portal controls exactly what they see when they try to connect. Microsoft also found indications that Storm-2945 may be targeting Android devices through the same landing pages, which include instructions to download and install an APK.

The second tool, ChocoShell, is a PowerShell infostealer that runs entirely in memory. Its primary target is credentials.

“ChocoShell collects Microsoft 365 and Azure Active Directory (AD) access tokens, refresh tokens, and Web Account Manager (WAM) tokens from .tbres files in the Token Broker cache. Collection of these tokens represents a significant threat to enterprise environments, as threat actors could replay SSO sessions without browser cookies.” states Microsoft. “Additionally, Wi-Fi credentials are harvested via netsh wlan show profile with key=clear.”

ChocoShell also implements three silent UAC bypass techniques with ordered fallback, disables Windows Defender signature updates, and uses Chrome DevTools Protocol to extract browser cookies by launching the browser with a remote debugging port. This technique bypasses Chrome’s App-Bound Encryption entirely.

Since July 16, some CaptiveCrunch landing pages have added device code phishing to the mix, redirecting guests into Microsoft’s legitimate device code authentication flow. The attacker initiates the authentication request and presents the user with a code to enter at Microsoft’s real sign-in page. When the user enters it, they authenticate the attacker’s session instead of their own — an MFA-satisfied session, since the user just completed the factor. Microsoft recommends blocking the device code flow through Conditional Access policies everywhere it isn’t explicitly required.

Researchers also detailed FruitStone, the web-based C2 panel used by Storm-2945 operators to manage the CaptiveCrunch campaign. It provides a centralized interface to control CornFlake implants, deploy payloads, collect stolen data, and manage compromised devices. Disguised as a legitimate “CloudSync Console,” it supports multi-operator access, agent monitoring, remote commands, file theft, credential collection, configuration updates, and campaign infrastructure management.

The practical advice for travelers is blunt: treat hotel, conference, and airport Wi-Fi as hostile. Use a mobile hotspot or cellular data instead wherever possible. Don’t download or execute anything a captive portal presents as an update, certificate, troubleshooting tool, or security utility. Don’t enter corporate credentials on venue registration pages. And if your organization hasn’t already blocked device code flow in Conditional Access, now is a reasonable time to check.

Recently, ReliaQuest’s threat research team also documented attackers compromising the Wi-Fi gateways at hotels and conference centers, then quietly rerouting guests toward fake Microsoft login pages.

There’s a pattern connecting all this to previous campaigns. The tradecraft echoes a Russian-linked operation called FrostArmada, which hit home routers the same way earlier this year, and researchers tie both to the group known as APT28 (aka UAC-0001, aka Fancy BearPawn StormSofacy GroupSednit, BlueDelta, and STRONTIUM). The link isn’t a smoking gun; it’s shared technique, not shared infrastructure, and the researchers say so plainly.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Hotel Wi-Fi)

UAC-0099 Is Now Hiding Malware Inside a Fake Notepad++ Plugin to Target Ukrainian Organizations

UAC-0099 delivers malware via a fake Notepad++ plugin after phishing, using a loader that sabotages itself if run without the correct arguments to hinder analysis.

CERT-UA published a new advisory attributing a phishing campaign to UAC-0099, a Russia-aligned threat actor active since at least mid-2022 and previously known for exploiting WinRAR vulnerabilities and using phishing emails to deliver malware families including LONEPAGE, MATCHBOIL, and DRAGSTARE.

UAC-0099

The latest campaign, observed earlier this summer, uses a trojanized Notepad++ plugin as the infection mechanism. It’s a meaningful change in delivery method for a group that’s been refining its toolset steadily for three years.

The attack starts with a phishing email carrying an image attachment. Clicking it opens a URL hidden behind a link shortener, which redirects to a file-sharing service such as EasySend[.]co where a ZIP archive waits. Inside the ZIP is a VBScript file disguised as a PDF document.

Running the VBScript triggers two things simultaneously. A legitimate decoy PDF downloads and opens in front of the victim to hold their attention, while in the background the script fetches a second archive called Evernote.zip. That archive contains a full working copy of Notepad++ version 8.8.3, a malicious DLL plugin named NppExport.dll, a password-protected RAR archive called updater.rar, and a legitimate WinRAR executable.

“The mentioned archive contains a VBS script with a double extension, the name of which may intentionally contain a significant number of spaces before the final .vbs extension , for example “Zavodskyi rayon.pdf .vbs”. In turn, when launched, the script will download a decoy file (for example “Zavodskyi rayon.pdf”) and the “Evernote.zip” archive.” reads the advisory. “The archive contains a full set of Notepad++ program components version 8.8.3, as well as the “/plugins/NppExport/” directory, which contains a third-party plugin library “NppExport.dll”, a password-protected archive “updater.rar” and the WinRAR executable file “winrar.exe”.”

The VBScript extracts everything and launches Notepad++, which loads NppExport.dll as it starts up. The victim sees a text editor open normally and has no reason to suspect anything happened.

The malicious DLL, codenamed LUNCHPOKE by CERT-UA, uses the bundled WinRAR binary to unpack the password-protected archive. That archive contains two files: RemoteLibUpdater.exe and InitTest.dll. LUNCHPOKE copies them to a specific directory and creates a scheduled task that runs RemoteLibUpdater.exe every three minutes. The three-minute interval is aggressive and keeps the implant active even after unexpected process termination.

“The file “NppExport.dll” is classified as a LUNCHPOKE utility , the main purpose of which is to create the directory ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\ “, extract the contents of the archive “updater.rar” to it using a password (in particular, the files “RemoteLibUpdater.exe” and “InitTest.dll”), copy the standard utility “schtasks.exe” to the file ” %PUBLIC%\Wallpapers\Background.exe ” and create a scheduled task with the name ” \W1n3r-U09oTy-Ap5\Updates ” to run the file ” %PUBLIC%\Libraries\fFthY3-Ytrevc3w-ab3\RemoteLibUpdater.exe ” with the arguments “setup nodisplay” every three minutes (the name of the directory ” fFthY3-Ytrevc3w-ab3 ” changes).” states CERT-UA.

RemoteLibUpdater.exe is BURNYBEAR, a loader whose job is to execute InitTest.dll. That DLL is a modified version of MATCHBOIL, a C#-based loader capable of fetching and running additional payloads, now designated MATCHBOIL.V2. The update indicates active development on the toolchain rather than a static deployment.

BURNYBEAR includes an unusual built-in sabotage behavior.

“The executable file “RemoteLibUpdater.exe” is classified as a BURNYBEAR utility , the functionality of which is designed to load the DLL file “InitTest.dll”. However, if “RemoteLibUpdater.exe” is launched incorrectly, namely without specifying arguments, BURNYBEAR instead activates logic designed to exhaust computer resources (RAM and CPU).” states the report.

That behavior serves a dual purpose: it makes behavioral analysis harder by producing unexpected output if someone runs the binary without the correct arguments, and it provides a rough sandbox detection mechanism since automated analysis environments often execute binaries without arguments.

This campaign arrives alongside a separate U.S. government advisory documenting Laundry Bear, another Russia-linked actor, running a phishing campaign against Zimbra mail servers belonging to Western government and commercial organizations since at least July 2025. That campaign uses a “half-click” exploit abusing CVE-2025-66376 to deliver malicious JavaScript called ZimReaper, which can harvest email communications without requiring the victim to click anything beyond opening a malicious email in a vulnerable webmail client. The U.S. government’s assessment of Laundry Bear’s intent is unambiguous:

CERT-UA recommends updating WinRAR, 7-Zip, and Notepad++ to their latest versions to close known vulnerabilities that groups like UAC-0099 use to facilitate follow-on stages once they’ve established a foothold.

The campaign’s use of a bundled legitimate WinRAR executable rather than relying on one already installed is notable: it means the attack chain doesn’t depend on the victim having a vulnerable version present, which makes the update recommendation more relevant as a general hygiene measure than as a specific remediation for this particular campaign. Organizations receiving unexpected emails with image attachments that open URLs through link shorteners should treat those as high-risk regardless of what the displayed content looks like.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Notepad++)

US Agencies Warn of Laundry Bear Campaign Targeting Unpatched Zimbra Servers

US agencies warn Russian group Laundry Bear is exploiting a patched Zimbra flaw to steal email accounts from organizations running unpatched servers.

The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI) and other U.S. government and international partners published a joint advisory to warn that the Russia-linked APT group Laundry Bear (aka Void Blizzard) is targeting organizations using unpatched Zimbra Collaboration servers.

The attackers exploit CVE-2025-66376, an XSS flaw that allows malicious JavaScript embedded in HTML emails to run automatically when viewed, enabling account theft without user interaction. The vulnerability was exploited as a zero-day before being patched and remains under active exploitation against unpatched systems.

“Unlike traditional phishing that attempts to persuade a user to take an action, such as clicking a link or downloading a file, LAUNDRY BEAR’s current campaign uses a zero-click exploit that only requires a user to view a malicious email within a vulnerable version of the ZCS webmail service.” reads the advisory. “This campaign uses a custom-developed aggregation and data exfiltration capability called Ulej to exploit a common vulnerabilities and exposures (CVE) in ZCS, CVE-2025-66376, with the potential for adaption to exploit other vulnerabilities as well. This advisory provides several mitigations to protect against this activity and specific remediation actions for organizations that detect indicators of compromise in their environment. “

LAUNDRY BEAR conducted a sophisticated campaign targeting Zimbra Collaboration Suite (ZCS) users by exploiting CVE-2025-66376, a zero-day vulnerability that enabled JavaScript execution directly from malicious emails.

“To gain initial access, LAUNDRY BEAR sends an email containing a malicious JavaScript payload to the target [T1566].” continues the advisory. “Through exploitation of CVE-2025-66376, this JavaScript payload is immediately executed once the user views the malicious email [T1203], such as the one shown in Figure 1, in the ZCS webmail platform.”

The group began exploiting the flaw before public disclosure and patch availability, demonstrating the ability of emerging threat actors to weaponize unknown vulnerabilities.

The attack starts with phishing emails sent from previously compromised accounts to evade detection and increase credibility. When victims open the message in Zimbra webmail, the embedded JavaScript executes through abused CSS @import directives.

“Hidden in LAUNDRY BEAR’s email is a Base64 encoded payload within the “onload” field of a Scalable Vector Graphics (SVG) element [T1027.017], as shown in Figure 3. Leading up to the inclusion of this payload in the SVG element are various instances of @import directives, as required to leverage CVE-2025-66376.” continues the advisory. “This payload includes an XOR encrypted final script encoded in a Base64 inner payload (see Figure 3) [T1027.013].”

The payload uses encryption and obfuscation techniques to bypass basic security controls and launches a multi-stage script designed for reconnaissance, credential theft, and data collection.

The malware attempts to maintain access by enabling IMAP, creating application passwords, harvesting two-factor authentication codes, and extracting saved browser password manager credentials. It collects mailbox information, user environment details, contacts, OAuth consumers, device status, and emails from the previous 90 days.

“LAUNDRY BEAR almost certainly relies on a mail client using the Internet Message Access Protocol (IMAP) for persistent access to the victim’s mailbox. During the enable_mail_protocols stage, a SOAP request leveraging the “ModifyPrefsRequest” command under the “ZimbraAccount” namespace is sent.” states the advisory. “This request attempts to set the “zimbraPrefImapEnabled” preference to TRUE. While the default setting for “zimbraPrefImapEnabled” is not well documented, this action is almost certainly intended to ensure that IMAP access to the victim’s mailbox is enabled.”

Collected data is exfiltrated through HTTPS and DNS channels to attacker-controlled infrastructure named Flowerbed, using a dedicated service called Catcher to receive and temporarily store stolen information. The campaign highlights the growing capability of smaller threat groups to exploit zero-days, bypass MFA protections, and compromise enterprise email environments for intelligence gathering and further attacks.

CISA released indicators of compromise (IOCs) linked to the LAUNDRY BEAR campaign, revealing that attackers used websites designed to impersonate legitimate Zimbra infrastructure. The threat actors registered deceptive domains, including mailnalysis.com, emailanalytics.com.ua, zimbrastat.com, zimbra-metadata.com, istc-cloud.com, and zmailanalytics.com, to support their operations and potentially collect stolen information.

To mitigate the risk, CISA recommends that organizations running Zimbra update their deployments to the latest available versions, review the published IOCs, and investigate possible connections to the identified domains and IP addresses. Organizations should also monitor authentication activity for anomalies, revoke unauthorized application passcodes, particularly those created with the “ZimbraWeb” identifier, and check user accounts for unauthorized mailbox access. In addition, CISA advises implementing phishing-resistant multi-factor authentication to reduce the risk of account compromise and limit the impact of similar campaigns.

In May, Netherlands General Intelligence and Security Service (AIVD) and the Netherlands Defence Intelligence and Security Service (MIVD) linked a previously undetected Russia-linked group, tracked Laundry Bear (aka Void Blizzard), to a 2024 police breach. In October 2024, the Dutch police blamed a state actor for the recent data breach that exposed officers’ contact details, the justice minister told lawmakers.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Zimbra)

Russian Hackers Used a Zimbra Zero-Day to Steal Emails Without Link Clicks

Russian hackers from the TA488 group exploited a Zimbra webmail flaw triggered when emails were opened or previewed, stealing credentials and up to 90 days of messages from victims.

Smashing Security podcast #477: How 14 orders of chicken McNuggets helped nail a suspected Russian hacker

A Russian intelligence-linked hacker is arrested in Thailand while enjoying a beach holiday - and the trail of evidence that nailed him to the Russian government includes 14 separate orders of chicken McNuggets. Meanwhile, AI music generator Suno has been hacked - and the stolen data appears to show exactly how much copyrighted music they hoovered up to train their models. All this and more in episode 477 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.

Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage

Dutch intelligence says Russia hacks IP cameras to monitor NATO military logistics and weapons shipments to Ukraine.

The Netherlands’ AIVD and MIVD, the civilian and military intelligence services, published a joint advisory on July 10 confirming that at least one Russian intelligence service is systematically compromising internet-connected IP cameras across the Netherlands, other EU and NATO member states, and Ukraine to collect military intelligence.

The operation is ongoing. The advisory is based on intelligence gathered by both services and covers a campaign that has escalated since Russia’s full-scale invasion of Ukraine.

The immediate military application in Ukraine is the most direct part of the finding.

“The information obtained by the Russian state actor via digital espionage operations targeting IP cameras provides insight into relevant military data, such as EU and NATO military transport routes and weapon deliveries to Ukraine. The Russian state actor uses image recognition software to conduct targeted searches for military vehicles and the military cargo they are transporting. In some cases, the access to IP cameras gained by the Russian state actor in Ukraine is used to identify the locations of Ukrainian military personnel.” reads the advisory. “Intelligence reveals that this information is subsequently used to neutralise Ukrainian military personnel and military materiel in use by the Ukrainian armed forces. Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.”

A roadside camera or a business camera overlooking a loading area becomes a targeting asset. That’s the direct line from a default password left unchanged to a strike on Ukrainian forces.

The surveillance operation in EU and NATO member states serves a different but related purpose.

“Furthermore, the Dutch services have determined that the Russian service is using the access to IP cameras to acquire relevant military intelligence in EU and NATO member states, including information that is not directly relevant to the war in Ukraine.” confirms the advisory. “To date, the Dutch services have not observed the Russian state actor using such information for military attacks outside Ukraine.”

The intelligence collected includes EU and NATO military transport routes and weapons deliveries bound for Kyiv. The Dutch services separately confirmed they caught a small number of cameras breached directly on military logistics routes inside the Netherlands, and warned the organizations running them so they could act.

The services are explicit that this isn’t a one-off campaign.

“The Dutch services assess that there has been a systematic increase in the number of digital espionage operations by Russian state actors to support military operations since the start of the war in Ukraine. The digital activities that target IP cameras form only a small part of their operations.” continues the joint advisory. “The Russian authorities derive significant tactical and strategic advantages from the deployment of cyber operations, from both defensive and offensive perspectives. For example, the MIVD has previously issued a warning about exploratory activities by Russian state actors targeting logistical routes, including routes in the Netherlands”

The camera surveillance is described as a small part of a much larger digital intelligence effort.

Getting into a camera isn’t technically sophisticated. The operators scan for internet-connected devices, fingerprint cameras by brand, and walk into those still running default passwords, outdated firmware, or factory settings. Once they’re in, image-recognition software runs automated searches through the video feed looking for military vehicles and the cargo they carry. No zero-days required.

“Once an IP camera has been identified, the malicious actor can attempt to gain access to the IP camera via the internet. This is often a relatively simple process, since many IP cameras that are connected to the internet lack adequate security measures.” states the advisory. “For example, they often have default passwords, obsolete firmware and factory configurations.”

The Dutch services have not observed the same camera-derived intelligence being used for military attacks outside Ukraine. But they say this demonstrates that Russia has the capability to do so, and that the same approach could be applied by Russian military units in a future conflict. That’s not a hypothetical being raised for rhetorical effect. It’s an assessment of demonstrated capability.

The most important variables, according to the advisory, are what the camera can see and whether it’s reachable from the public internet. On the first: cameras should be positioned for their actual purpose and should avoid covering logistics routes, loading docks, ports, or any area where military movements or weapons shipments pass. Sensitive zones within the field of view should be masked or blurred where possible, and GPS location data should be stripped from video streams.

On accessibility: live streams should not be publicly reachable unless there’s an essential reason for it. Port forwarding and UPnP should be disabled. Remote access should go through a VPN rather than direct exposure. Default passwords should be changed immediately on installation, admin accounts should be kept separate from stream-viewing accounts, and MFA should be enabled wherever the device supports it. The advisory also flags the origin of the hardware itself: China, Russia, and Iran are cited as countries actively running offensive cyber programs targeting Dutch and European interests, and buyers should factor that into procurement decisions.

Cybersecurity firm Censys counted more than 87,000 internet-connected cameras across EU and NATO countries and Ukraine running services matching known-exploited vulnerabilities. In the Netherlands alone, more than 45,000 cameras are reachable from the public internet.

The numbers illustrate the scale of the exposed surface the advisory is addressing. Fixing it doesn’t require new technology. It requires treating a camera pointing at a transport route with the same security discipline as any other system connected to the internet.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, IP cameras)

❌