Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Group Linked to Malware Attacks on Ukraine

Russian Group Linked to Malware Attacks on Ukraine

Posted on February 13, 2026 By CWS

In a recent development, a newly identified cyber threat actor has been linked to attacks on Ukrainian organizations using a malware variant named CANFAIL. According to the Google Threat Intelligence Group (GTIG), the cybercriminal group is suspected of having connections with Russian intelligence services. Their primary targets include defense, military, government, and energy sectors within Ukraine.

Expanding Targets and Tactics

Beyond these sectors, the group has shown increasing interest in aerospace and manufacturing entities linked to military and drone technology, as well as nuclear and chemical research bodies. Additionally, international organizations focusing on conflict monitoring and humanitarian efforts in Ukraine have also been targeted by the hackers.

Despite being less organized and funded compared to other Russian hacking groups, the attackers are evolving by leveraging large language models (LLMs) to enhance their technical capabilities. These models assist them in conducting reconnaissance, designing social engineering baits, and resolving basic technical queries related to post-compromise activities and command-and-control (C2) infrastructure.

Phishing Strategies and Techniques

The group’s phishing campaigns often involve impersonating legitimate Ukrainian energy firms to gain unauthorized access to personal and corporate email accounts. They have also been observed masquerading as a Romanian energy company with Ukrainian connections and targeting Romanian and Moldovan entities.

Central to their operations is the creation of targeted email lists based on geographical and industrial research. Their attack vectors frequently employ LLM-generated lures and contain Google Drive links that lead to a RAR archive with the CANFAIL malware.

Technical Characteristics of CANFAIL Malware

The CANFAIL malware, often disguised with a double extension to appear as a PDF document, is actually obfuscated JavaScript. Once executed, it runs a PowerShell script that downloads and executes an in-memory PowerShell dropper while showing a fake error message to the victim.

GTIG has also associated this threat actor with a campaign named PhantomCaptcha, identified by SentinelOne’s SentinelLABS in October 2025. This campaign targeted Ukrainian war relief organizations through phishing emails that redirected users to counterfeit pages designed to initiate the infection process using a WebSocket-based trojan.

As the situation develops, organizations are urged to enhance their cybersecurity measures to defend against such sophisticated cyber threats, particularly those originating from state-sponsored actors.

The Hacker News Tags:CANFAIL, cyber attacks, Cybersecurity, Defense, energy sector, GTIG, Malware, Phishing, Russian hackers, Ukraine

Post navigation

Previous Post: XWorm RAT Campaign Evades Detection with Excel Exploit
Next Post: Fake AI Chrome Extensions Compromise Over 260,000 Users

Related Posts

CISOs Tackle Burnout and Reduce MTTR Without Extra Staff CISOs Tackle Burnout and Reduce MTTR Without Extra Staff The Hacker News
Why Executives and Practitioners See Risk Differently Why Executives and Practitioners See Risk Differently The Hacker News
251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch 251 Amazon-Hosted IPs Used in Exploit Scan Targeting ColdFusion, Struts, and Elasticsearch The Hacker News
Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign Cybercriminals Abuse Google Cloud Email Feature in Multi-Stage Phishing Campaign The Hacker News
Why CTEM is the Winning Bet for CISOs in 2025 Why CTEM is the Winning Bet for CISOs in 2025 The Hacker News
PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain PyPI Warns of Ongoing Phishing Campaign Using Fake Verification Emails and Lookalike Domain The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Global Cyber Threats Target Defense Sector Amid Rising Tensions
  • Fake AI Chrome Extensions Compromise Over 260,000 Users
  • Russian Group Linked to Malware Attacks on Ukraine
  • XWorm RAT Campaign Evades Detection with Excel Exploit
  • UAT-9921 Targets Tech and Finance with VoidLink Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Global Cyber Threats Target Defense Sector Amid Rising Tensions
  • Fake AI Chrome Extensions Compromise Over 260,000 Users
  • Russian Group Linked to Malware Attacks on Ukraine
  • XWorm RAT Campaign Evades Detection with Excel Exploit
  • UAT-9921 Targets Tech and Finance with VoidLink Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News