Researchers at F6 reported a new wave of financially motivated attacks by Hive0117 targeting accountants at companies in Russia and other CIS countries, using phishing emails disguised as routine accounting documents. The messages carry password-protected RAR archives that infect victims with the fileless DarkWatchman malware and a keylogger, giving the attackers access to remote banking systems used by businesses. Victims have also been identified in Belarus, Kazakhstan, and Uzbekistan, and the group has reportedly been active since at least 2021.
F6 estimates Hive0117 has conducted about 400 successful intrusions since the start of the year, with average losses rising from 3 million to 10 million rubles. In the latest campaign, the group reportedly shifted from direct theft to fraudulent payroll register payments, making unauthorized transfers appear to be legitimate salary disbursements while routing the money to drop accounts. The operation highlights continued targeting of finance departments through credential theft, keylogging, and abuse of trusted business payment workflows.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
F6 researchers reported a new wave of Hive0117 attacks in which phishing emails with password-protected RAR archives infect accountants with fileless DarkWatchman malware and a keylogger. In this campaign, the group reportedly shifted from direct transfers to fraudulent payroll register payments that disguise theft as salary disbursements.
F6 researchers said Hive0117 has conducted about 400 successful attacks against Russian organizations since the start of the year, targeting company accountants to steal money through remote banking systems. Average losses reportedly rose from 3 million to 10 million rubles.
After targeting Eriell Group, a Tashkent-based oilfield services company with operations in Russia, the Nova ransomware group reportedly acknowledged the victim was CIS-linked. Nova said the responsible affiliate was cut off and banned, and publicly claimed encryption did not occur and data was not published.
Sekoia.io's Operation Phantom Net Voxel attributed to APT28 reportedly compromised 42 hosts belonging to Ukrainian military structures. The campaign used spearphishing via weaponized Office documents delivered through email and Signal Desktop, then deployed BEARDSHELL, COVENANT, and SLIMAGENT.
Attackers carried out a credential stuffing incident against a corporate VPN gateway using valid employee usernames and recently stolen passwords sourced from Lumma stealer logs. The case illustrated how infostealer infections on personal or unmanaged devices can lead to organizational compromise through valid accounts.
Recently stolen passwords from Lumma stealer logs appeared on Russian Market one day before they were used in a credential stuffing incident against a corporate VPN gateway. The exposure created the opportunity for attackers to reuse valid employee usernames and passwords.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourcecodeby.net
Open sourcecodeby.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.