Russian authorities said foreign hackers acting as cyber mercenaries breached multiple federal executive bodies and stole confidential information in a targeted campaign uncovered in 2020. A joint report from Rostelecom-Solar and the National Coordination Center for Computer Incidents said the intruders used three primary access routes: tailored spear-phishing, exploitation of internet-facing web application flaws, and compromises of government contractors that enabled trusted-relationship access into agency networks.
After gaining entry, the attackers conducted internal reconnaissance, targeted administrators’ workstations and infrastructure management systems, and collected data from mail servers, document management platforms, file servers, and employee endpoints. Investigators said the operation relied on previously unseen malware, including Mail-O and Webdav-O, to provide stealthy backdoor access, execute commands, and exfiltrate data through Russian cloud services while mimicking legitimate Yandex Disk and Mail.ru Disk-O traffic. The report also said the attackers tailored their activity to evade detection by deployed security tools, including abuse of legitimate components of a widely used Russian antivirus product to gather information about victim networks.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
Russian authorities publicly disclosed a joint Rostelecom-Solar and NKTsKI report describing the campaign's tactics, including spear-phishing, web application exploitation, and contractor compromise. The report also revealed two previously unseen malware strains, Mail-O and Webdav-O, used as stealthy backdoors and for data exfiltration via Russian cloud services while mimicking legitimate Yandex.Disk and Disk-O traffic.
Solar JSOC specialists at Rostelecom-Solar, together with Russia's National Coordination Center for Computer Incidents, identified a series of targeted intrusions affecting Russian federal executive authorities. The attacks involved theft of confidential information and were later assessed as the work of cyber mercenaries acting in the interests of a foreign state.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcert-solar.ru
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.