Tag Kaspersky

The Kremlin’s Cunning Hacking Group Leverages Russian ISPs to Deploy Spyware

The Russian hacker group Turla, known for their advanced cyberespionage techniques, has been linked to a new spying method that demonstrates their sophisticated approach to cyber operations. This group has made headlines for utilizing unorthodox methods, such as embedding malware communications in satellite connections or commandeering other hackers’ operations to…

Read MoreThe Kremlin’s Cunning Hacking Group Leverages Russian ISPs to Deploy Spyware

Researchers Discover Batavia Windows Spyware Targeting Russian Firms to Steal Documents

Cyber Espionage / Threat Intelligence
July 08, 2025

An ongoing cyber-espionage campaign has been identified, targeting Russian organizations with a new strain of Windows spyware known as Batavia. According to cybersecurity firm Kaspersky, the operation has been active since July 2024. The attack typically begins with phishing emails that contain malicious links, disguised as communications regarding contract agreements. “The primary objective of this attack is to deploy the previously unknown Batavia spyware to steal internal documents from the targeted organizations,” Kaspersky reported. These emails originate from the domain “oblast-ru[.]com,” believed to be controlled by the attackers. The links in these emails lead recipients to download an archive file that contains a malicious Visual Basic Encoded script (.VBE). Once executed, the script gathers system information from the compromised host and transmits it to a remote server, paving the way for the subsequent delivery of a next-stage payload.

Unveiling Batavia: New Spyware Targeting Russian Firms for Cyber Espionage In a recent development within the sphere of cyber espionage, researchers have identified a previously unreported piece of Windows spyware dubbed Batavia, specifically designed to infiltrate Russian organizations. This activity, which cybersecurity firm Kaspersky reports has been ongoing since July…

Read More

Researchers Discover Batavia Windows Spyware Targeting Russian Firms to Steal Documents

Cyber Espionage / Threat Intelligence
July 08, 2025

An ongoing cyber-espionage campaign has been identified, targeting Russian organizations with a new strain of Windows spyware known as Batavia. According to cybersecurity firm Kaspersky, the operation has been active since July 2024. The attack typically begins with phishing emails that contain malicious links, disguised as communications regarding contract agreements. “The primary objective of this attack is to deploy the previously unknown Batavia spyware to steal internal documents from the targeted organizations,” Kaspersky reported. These emails originate from the domain “oblast-ru[.]com,” believed to be controlled by the attackers. The links in these emails lead recipients to download an archive file that contains a malicious Visual Basic Encoded script (.VBE). Once executed, the script gathers system information from the compromised host and transmits it to a remote server, paving the way for the subsequent delivery of a next-stage payload.

Russia’s National Airline Halts Flights Following Cyber Attack

Critical Infrastructure Security, Cyberwarfare / Nation-State Attacks, Fraud Management & Cybercrime Aeroflot Targeted by Belarusian Hackers Using Wiper Malware Mathew J. Schwartz (euroinfosec) • July 28, 2025 Image: Media_works/Shutterstock Aeroflot, Russia’s state-owned airline, has canceled numerous flights following a cyberattack attributed to a Belarusian hacking collective. The group, known as…

Read MoreRussia’s National Airline Halts Flights Following Cyber Attack

Mirai Botnet Variant Takes Advantage of DVR Vulnerability to Form Swarm

Endpoint Security, Internet of Things Security Variant of Mirai Botnet Exploits DVR Command Injection Vulnerability, Impacting 50,000 Devices Anviksha More (AnvikshaMore) • June 9, 2025 Image: Ivan Kislitsin/Shutterstock A newly identified variant of the Mirai botnet is making headlines as it exploits a command injection vulnerability in internet-connected digital video…

Read MoreMirai Botnet Variant Takes Advantage of DVR Vulnerability to Form Swarm

Chinese APT IronHusky Unleashes Updated MysterySnail RAT Targeting Russia

Researchers at Kaspersky have identified the resurgence of MysterySnail RAT, a Remote Access Trojan (RAT) previously associated with the Chinese cyber espionage group IronHusky APT. After remaining dormant for years, the malware is now targeting government entities in Mongolia and Russia. This renewed activity highlights the evolving tactics of cybercriminals…

Read MoreChinese APT IronHusky Unleashes Updated MysterySnail RAT Targeting Russia