DarkWatchman cybercrime malware returns on Russian networks
一个名为Hive0117的黑客组织针对俄罗斯多个行业的公司发起了钓鱼攻击,使用了修改版的DarkWatchman恶意软件。攻击伪装成政府通信或征兵通知,附件包含恶意存档,感染系统后可记录键盘输入和收集数据。这些攻击可能与俄乌冲突无关,且该组织的起源不明。同时,俄罗斯骗子 increasingly 使用AI和社会工程进行诈骗。 2025-4-30 15:16:16 Author: therecord.media(查看原文) 阅读量:31 收藏

A financially motivated hacker group has targeted Russian companies across several industries in a new phishing campaign using a modified version of the DarkWatchman malware, researchers have found.

The group, known as Hive0117, has attacked firms in sectors including media, tourism, biotechnology, finance, energy and telecommunications, according to Russian cybersecurity firm F6. 

In 2023, Western researchers spotted the group spoofing Russian government communications and sending phishing emails disguised as military conscription notices. DarkWatchman was part of that campaign. 

The recent activity detailed by F6 involved phishing emails containing password-protected malicious archives. Once opened, the malware infected systems, allowing the hackers to record keystrokes, collect data and deploy additional payloads.

It is unclear whether the latest attacks were successful or caused any financial damage. The group’s activity, which dates back to at least February 2022, does not appear to be linked to the ongoing cyber conflict between Russia and Ukraine, researchers previously said. Hive0117's origins remain unknown.

In previous operations, the hackers impersonated legitimate organizations and targeted entities in Russia, Belarus, Lithuania, Estonia and Kazakhstan.

Earlier this week, Russian media reported that scammers in Russia are increasingly using artificial intelligence and social engineering to defraud local users. Posing as potential partners on dating apps or social media, the fraudsters build trust before soliciting money for fake investments or business schemes, according to the reports.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.


文章来源: https://therecord.media/darkwatchman-malware-russia-cybercrime-hive0117
如有侵权请联系:admin#unsafe.sh