Multi-stage phishing campaign targeting users in Russia with Amnesia RAT and ransomware
Campaign
Summary
Hide ▲
Show ▼
A multi-stage phishing campaign is targeting users in Russia, delivering Amnesia RAT and ransomware that enable credential theft, remote control, and destructive payload execution. The operation matters because it combines staged delivery, cloud-hosted payloads, and security evasion to increase compromise success and resilience.
Related Happenings
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor Meta
H score14
First: 13.07.2026 18:30
Last: 13.07.2026 18:30
Sources 1
About this happening:
The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
The Quarry PaaS ecosystem and RockyBelling's promotion of MaDoO Blaster
Threat Actor MetaAbout this happening: The Quarry was tied to MaDoO Blaster, showing a phishing-as-a-service ecosystem that packages AiTM tooling for sale. The operation was run by RockyBelling, who pro...
ModeloRAT malicious PowerShell and Dropbox delivery activity
Malware Activity
H score16
First: 14.05.2026 15:12
Last: 14.05.2026 15:12
Sources 1
About this happening:
The ModeloRAT activity now uses a malicious PowerShell command and a Dropbox ZIP payload to gain persistent footholds, enabling system reconnaissance, screenshot...
ModeloRAT malicious PowerShell and Dropbox delivery activity
Malware ActivityAbout this happening: The ModeloRAT activity now uses a malicious PowerShell command and a Dropbox ZIP payload to gain persistent footholds, enabling system reconnaissance, screenshot...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/Mitigation
H score34
First: 07.05.2026 21:00
Last: 07.05.2026 21:00
Sources 1
About this happening:
The ACSC issued mitigation guidance for an ongoing ClickFix campaign that is pushing Vidar Stealer through malicious PowerShell commands, increasing credential-the...
ACSC ClickFix mitigation guidance for Vidar Stealer
Advisory/MitigationAbout this happening: The ACSC issued mitigation guidance for an ongoing ClickFix campaign that is pushing Vidar Stealer through malicious PowerShell commands, increasing credential-the...
APT28 Windows Shell LNK campaign targeting Ukraine and E.U. nations
Campaign
H score39
First: 28.04.2026 08:50
Last: 28.04.2026 08:50
Sources 1
About this happening:
A December 2025 APT28 campaign targeted Ukraine and E.U. nations with a malicious Windows Shortcut (LNK) chain that bypassed Microsoft Defender SmartScreen...
APT28 Windows Shell LNK campaign targeting Ukraine and E.U. nations
CampaignAbout this happening: A December 2025 APT28 campaign targeted Ukraine and E.U. nations with a malicious Windows Shortcut (LNK) chain that bypassed Microsoft Defender SmartScreen...
REF6598 Obsidian social-engineering campaign targeting finance and crypto users
Campaign
H score35
First: 16.04.2026 14:02
Last: 16.04.2026 14:02
Sources 1
About this happening:
The REF6598 operation is using LinkedIn, Telegram, and Obsidian to deliver PHANTOMPULSE, creating a targeted intrusion path into financial and cryptocurr...
REF6598 Obsidian social-engineering campaign targeting finance and crypto users
CampaignAbout this happening: The REF6598 operation is using LinkedIn, Telegram, and Obsidian to deliver PHANTOMPULSE, creating a targeted intrusion path into financial and cryptocurr...
Timeline
-
24.01.2026 13:09 2 articles · 5mo ago
Fortinet discloses Russia-targeted multi-stage phishing campaign
Initial DisclosureFortinet FortiGuard Labs described a multi-stage phishing campaign targeting users in Russia that uses business-themed documents, malicious LNK files, PowerShell, GitHub-hosted scripts, Dropbox-hosted binaries, and defendnot to disable Microsoft Defender before delivering Amnesia RAT and a Hakuna Matata-derived ransomware.
Show sources
- Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware — thehackernews.com — 24.01.2026 13:09
- Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware — thehackernews.com — 24.01.2026 13:09