Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization

A graduate student at Stanford University has created an algorithm to help classmates find love. Now, Date Drop is the foundation of his new startup

Google connects China, Iran, Russia, and North Korea to coordinate defense sector cyber operations

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization
Identity

Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization

userBy userFebruary 13, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Ravi LakshmananFebruary 13, 2026Threat Intelligence/Malware

A previously undocumented attacker is believed to have targeted organizations in Ukraine using malware known as CANFAIL.

The Google Threat Intelligence Group (GTIG) said the hacking group may have ties to Russian intelligence services. The attacker is assessed to be targeting defense, military, government, and energy organizations within local and central governments in Ukraine.

However, GTIG added that the group is also increasingly interested in aerospace agencies, military and drone manufacturing companies, nuclear and chemical research institutes, and international organizations involved in conflict monitoring and humanitarian assistance in Ukraine.

“Despite being less sophisticated and resourceful than other Russian threat groups, this actor has recently begun to use LLM to overcome some technical limitations.” [large language models]” said GTIG.

“Through prompts, they conduct reconnaissance, create social engineering lures, and look for answers to basic technical questions about post-compromise activities and C2 infrastructure setup.”

Recent phishing campaigns have seen attackers impersonate legitimate Ukrainian national and local energy organizations to gain unauthorized access to organizational and personal email accounts.

The group is said to have targeted Romanian companies and spied on organizations in Moldova, as well as posing as a Romanian energy company doing business with customers in Ukraine.

To enable their operations, attackers use research to generate email address lists tailored to specific regions or industries. The attack chain appears to include an LLM-generated decoy with an embedded Google Drive link pointing to a RAR archive containing the CANFAIL malware.

CANFAIL is typically obfuscated JavaScript malware disguised with a double extension to disguise itself as a PDF document (*.pdf.js) and designed to run a PowerShell script that downloads and executes a memory-only PowerShell dropper. At the same time, it displays a fake “error” message to the victim.

According to Google, this attacker is also associated with a campaign known as PhantomCaptcha revealed by SentinelOne SentinelLABS in October 2025 that targeted organizations associated with war relief efforts in Ukraine through phishing emails that directed recipients to a fake page hosting ClickFix-style instructions to activate an infection sequence and deliver a WebSocket-based Trojan.


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA graduate student at Stanford University has created an algorithm to help classmates find love. Now, Date Drop is the foundation of his new startup
user
  • Website

Related Posts

Google connects China, Iran, Russia, and North Korea to coordinate defense sector cyber operations

February 13, 2026

UAT-9921 Deploys VoidLink malware targeting technology and financial sectors

February 13, 2026

Malicious Chrome extension discovered to be stealing business data, email, and browsing history

February 13, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Google collaborates with Russian actor suspect in failed malware attack on Ukrainian organization

A graduate student at Stanford University has created an algorithm to help classmates find love. Now, Date Drop is the foundation of his new startup

Google connects China, Iran, Russia, and North Korea to coordinate defense sector cyber operations

Dutch mobile phone giant Odid announces millions of customers affected by data breach

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.