Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Russian Group Linked to Malware Attacks on Ukraine

Russian Group Linked to Malware Attacks on Ukraine

Posted on February 13, 2026 By CWS

In a recent development, a newly identified cyber threat actor has been linked to attacks on Ukrainian organizations using a malware variant named CANFAIL. According to the Google Threat Intelligence Group (GTIG), the cybercriminal group is suspected of having connections with Russian intelligence services. Their primary targets include defense, military, government, and energy sectors within Ukraine.

Expanding Targets and Tactics

Beyond these sectors, the group has shown increasing interest in aerospace and manufacturing entities linked to military and drone technology, as well as nuclear and chemical research bodies. Additionally, international organizations focusing on conflict monitoring and humanitarian efforts in Ukraine have also been targeted by the hackers.

Despite being less organized and funded compared to other Russian hacking groups, the attackers are evolving by leveraging large language models (LLMs) to enhance their technical capabilities. These models assist them in conducting reconnaissance, designing social engineering baits, and resolving basic technical queries related to post-compromise activities and command-and-control (C2) infrastructure.

Phishing Strategies and Techniques

The group’s phishing campaigns often involve impersonating legitimate Ukrainian energy firms to gain unauthorized access to personal and corporate email accounts. They have also been observed masquerading as a Romanian energy company with Ukrainian connections and targeting Romanian and Moldovan entities.

Central to their operations is the creation of targeted email lists based on geographical and industrial research. Their attack vectors frequently employ LLM-generated lures and contain Google Drive links that lead to a RAR archive with the CANFAIL malware.

Technical Characteristics of CANFAIL Malware

The CANFAIL malware, often disguised with a double extension to appear as a PDF document, is actually obfuscated JavaScript. Once executed, it runs a PowerShell script that downloads and executes an in-memory PowerShell dropper while showing a fake error message to the victim.

GTIG has also associated this threat actor with a campaign named PhantomCaptcha, identified by SentinelOne’s SentinelLABS in October 2025. This campaign targeted Ukrainian war relief organizations through phishing emails that redirected users to counterfeit pages designed to initiate the infection process using a WebSocket-based trojan.

As the situation develops, organizations are urged to enhance their cybersecurity measures to defend against such sophisticated cyber threats, particularly those originating from state-sponsored actors.

The Hacker News Tags:CANFAIL, cyber attacks, Cybersecurity, Defense, energy sector, GTIG, Malware, Phishing, Russian hackers, Ukraine

Post navigation

Previous Post: XWorm RAT Campaign Evades Detection with Excel Exploit
Next Post: Fake AI Chrome Extensions Compromise Over 260,000 Users

Related Posts

New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones New Android Banking Trojan “Klopatra” Uses Hidden VNC to Control Infected Smartphones The Hacker News
Critical Cisco Unified CM Flaw Actively Exploited Critical Cisco Unified CM Flaw Actively Exploited The Hacker News
Critical Windows Flaw Allows SYSTEM Privilege Escalation Critical Windows Flaw Allows SYSTEM Privilege Escalation The Hacker News
Global SMS Scams Exploit Fake CAPTCHA and Keitaro Tools Global SMS Scams Exploit Fake CAPTCHA and Keitaro Tools The Hacker News
SmartLoader Malware Exploits Oura Server for Data Theft SmartLoader Malware Exploits Oura Server for Data Theft The Hacker News
Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • WhatsApp Introduces Usernames for Enhanced Privacy
  • Turla’s Advanced Espionage Operations in Ukraine Uncovered
  • Researchers Expose New Attack on Developer Systems
  • Linux Kernel Vulnerabilities Highlight Security Concerns
  • Millenium RAT Malware Threat Grows, Infections Skyrocket

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark