Russian cybersecurity firm F6 says a previously undocumented espionage group it calls SiribClone has targeted Russian military personnel since at least summer 2025, using fake romantic interest and humanitarian-assistance pretexts on Telegram, messaging apps, and dating sites to collect battlefield-relevant intelligence. The operation sought personal data, correspondence, contacts, geolocation, device information, and access to victims’ Telegram accounts, with activity concentrated on servicemen in border regions and combat zones.
Researchers identified two malware families tied to the campaign: SafeLoveStealer for Android, spread through deceptive links and APK files such as Safeintim.apk, and SiribGrabber for Windows, delivered through .LNK files disguised as military-themed documents and later through an "Immortal Regiment" themed website serving malicious archives. F6 also found phishing infrastructure designed to steal Telegram sessionString tokens and an internal operator platform called Kontur used to store hijacked Telegram sessions, review intercepted messages, and track victim details; the company did not attribute the activity to a known threat actor or country.

Pull IOCs and campaign context straight into your stack.
5 events from the most recent confirmed update back to the earliest known activity.
F6 reported that the previously undocumented espionage group SiribClone has targeted Russian military personnel since at least summer 2025 using social-engineering lures on Telegram and other platforms.
F6 publicly reported on the SiribClone operation, describing romance and humanitarian-assistance lures targeting Russian soldiers, the SafeLoveStealer Android spyware, the SiribGrabber desktop malware, Telegram credential theft infrastructure, and the internal 'Kontur' platform used to manage stolen Telegram sessions.
In May 2026, F6 observed a new SiribClone campaign using an 'Immortal Regiment' themed website to entice victims to download archives that deployed an updated SiribGrabber malware variant.
F6 observed attacks during January and February 2026 in which SiribClone used messengers and dating sites to phish Russian military personnel and deliver Android spyware and Windows malware.
According to F6, SiribClone began testing its malware tooling in December 2025 ahead of later observed attacks against Russian servicemen.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Pull the IOCs, campaigns, and victimology behind this family, ready to push into your SIEM and EDR.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.