SiribClone is a previously undocumented cyber-espionage group active since at least summer 2025 that targets Russian military personnel, particularly servicemen stationed in border regions and combat zones. The operation is assessed as military intelligence collection focused on harvesting personal, geographic, technical, and communications data from members of the Russian armed forces. The group relies heavily on social engineering and phishing delivered through Telegram and other messaging platforms. Operators have impersonated women seeking romantic relationships and volunteers offering humanitarian assistance, using trust-building conversations to persuade targets to install malicious Android applications or submit Telegram authentication details to spoofed web pages. SiribClone has also used themed lures tied to military or patriotic subjects and distributed malware through archives disguised as military-related documents. Observed tooling includes the Android spyware SafeLoveStealer and the desktop malware SiribGrabber. SafeLoveStealer is used to collect files, device information, geolocation, and other data from infected Android devices, and can activate the microphone to record conversations. SiribGrabber is used on desktop systems to steal files and support ongoing collection from compromised hosts. Reporting also indicates the group sought persistence on Windows systems and maintained infrastructure to manage stolen access. A notable component of the operation is Telegram account compromise. SiribClone operated phishing pages masquerading as Telegram login and invitation workflows and captured authentication material that enabled takeover of victims’ Telegram accounts. The group maintained an internal operator platform known as Kontur for storing stolen Telegram sessions and reviewing intercepted messages, with victim notes referencing ranks, unit affiliations, locations, and operational status. This strongly indicates a structured espionage program aimed at monitoring military communications and extracting battlefield-relevant intelligence. No high-confidence attribution to a specific country or known threat actor cluster is currently available.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
Attributed origin per open-source reporting.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 malware families attributed to this actor across reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Targeted Russian military personnel with Telegram-based phishing and Android spyware.
Cyber espionage campaign targeting Russian military personnel through romance and humanitarian-assistance lures to steal files, monitor communications, collect battlefield intelligence, and hijack Telegram accounts.
Cyber-espionage group targeting Russian military personnel to collect personal data, geolocation, correspondence, contacts, and other intelligence-relevant information using phishing, social engineering, Android spyware, and Windows malware.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.