Google Threat Intelligence Group (GTIG) attributed a previously undocumented threat actor—assessed as possibly affiliated with Russian intelligence services—to phishing-led intrusions delivering CANFAIL, an obfuscated JavaScript malware used against Ukrainian organizations. Targeting has focused on defense, military, government, and energy entities, with reported expansion into aerospace, manufacturing tied to military/drone supply chains, nuclear/chemical research, and international organizations involved in conflict monitoring and humanitarian aid. GTIG reported the actor has begun using LLMs to compensate for limited sophistication, including generating reconnaissance outputs, crafting social-engineering lures, and seeking guidance for post-compromise actions and C2 setup.
The observed infection chain uses LLM-generated phishing lures and Google Drive links that deliver a RAR archive containing CANFAIL, often disguised with a double extension such as *.pdf.js to appear benign. CANFAIL is designed to execute a PowerShell script to continue execution and enable follow-on activity. GTIG also noted regional spillover and related targeting, including impersonation of Ukrainian energy organizations and a Romanian energy company serving customers in Ukraine, plus activity against a Romanian firm and reconnaissance on Moldovan organizations; the actor reportedly builds tailored email lists by region and industry to support these campaigns.

Get the infrastructure and lures behind it.
3 events from the most recent confirmed update back to the earliest known activity.
Google Threat Intelligence Group publicly tied the CANFAIL malware attacks to a previously undocumented suspected Russian threat actor and described the group's expanding targeting priorities. GTIG also said the actor was using large language models to aid reconnaissance, lure creation, and basic post-compromise tasks.
A previously undocumented threat actor assessed as possibly affiliated with Russian intelligence services carried out phishing campaigns delivering CANFAIL malware against Ukrainian organizations. Primary targets included defense, military, government, and energy entities, with additional targeting or reconnaissance involving Romania and Moldova.
SentinelLABS and the Digital Security Lab of Ukraine documented the "PhantomCaptcha" campaign in October 2025. This activity was later linked to the same suspected Russia-aligned actor associated with CANFAIL malware operations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
wiu.edu
Open sourcesecurityaffairs.com
Open sourcethehackernews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.