Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Group Linked to Malware Attacks on Ukraine

Russian Group Linked to Malware Attacks on Ukraine

Posted on February 13, 2026 By CWS

In a recent development, a newly identified cyber threat actor has been linked to attacks on Ukrainian organizations using a malware variant named CANFAIL. According to the Google Threat Intelligence Group (GTIG), the cybercriminal group is suspected of having connections with Russian intelligence services. Their primary targets include defense, military, government, and energy sectors within Ukraine.

Expanding Targets and Tactics

Beyond these sectors, the group has shown increasing interest in aerospace and manufacturing entities linked to military and drone technology, as well as nuclear and chemical research bodies. Additionally, international organizations focusing on conflict monitoring and humanitarian efforts in Ukraine have also been targeted by the hackers.

Despite being less organized and funded compared to other Russian hacking groups, the attackers are evolving by leveraging large language models (LLMs) to enhance their technical capabilities. These models assist them in conducting reconnaissance, designing social engineering baits, and resolving basic technical queries related to post-compromise activities and command-and-control (C2) infrastructure.

Phishing Strategies and Techniques

The group’s phishing campaigns often involve impersonating legitimate Ukrainian energy firms to gain unauthorized access to personal and corporate email accounts. They have also been observed masquerading as a Romanian energy company with Ukrainian connections and targeting Romanian and Moldovan entities.

Central to their operations is the creation of targeted email lists based on geographical and industrial research. Their attack vectors frequently employ LLM-generated lures and contain Google Drive links that lead to a RAR archive with the CANFAIL malware.

Technical Characteristics of CANFAIL Malware

The CANFAIL malware, often disguised with a double extension to appear as a PDF document, is actually obfuscated JavaScript. Once executed, it runs a PowerShell script that downloads and executes an in-memory PowerShell dropper while showing a fake error message to the victim.

GTIG has also associated this threat actor with a campaign named PhantomCaptcha, identified by SentinelOne’s SentinelLABS in October 2025. This campaign targeted Ukrainian war relief organizations through phishing emails that redirected users to counterfeit pages designed to initiate the infection process using a WebSocket-based trojan.

As the situation develops, organizations are urged to enhance their cybersecurity measures to defend against such sophisticated cyber threats, particularly those originating from state-sponsored actors.

The Hacker News Tags:CANFAIL, cyber attacks, Cybersecurity, Defense, energy sector, GTIG, Malware, Phishing, Russian hackers, Ukraine

Post navigation

Previous Post: XWorm RAT Campaign Evades Detection with Excel Exploit
Next Post: Fake AI Chrome Extensions Compromise Over 260,000 Users

Related Posts

North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages The Hacker News
Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature The Hacker News
Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads Phishing Campaign Uses UpCrypter in Fake Voicemail Emails to Deliver RAT Payloads The Hacker News
Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks Pre-Auth Exploit Chains Found in Commvault Could Enable Remote Code Execution Attacks The Hacker News
One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief One Click Can Turn Perplexity’s Comet AI Browser Into a Data Thief The Hacker News
Europol Dismantles 0 Million Cryptocurrency Fraud Network, Arrests Five Suspects Europol Dismantles $540 Million Cryptocurrency Fraud Network, Arrests Five Suspects The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • BlankGrabber Stealer Conceals Malware with Fake Certificates
  • Critical Vulnerability in Open VSX Exposes Users to Risk
  • TA446 Hackers Unleash DarkSword Kit on iOS Devices
  • Rundll32 and WebDAV: New ClickFix Variant Evades Detection
  • OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • BlankGrabber Stealer Conceals Malware with Fake Certificates
  • Critical Vulnerability in Open VSX Exposes Users to Risk
  • TA446 Hackers Unleash DarkSword Kit on iOS Devices
  • Rundll32 and WebDAV: New ClickFix Variant Evades Detection
  • OpenAI Resolves ChatGPT Data Breach and Codex Vulnerability

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark