216.73.216.6

Batavia spyware steals data from Russian organizations

· Published 07/07/2025 13:55 · Modified 13/07/2025 09:50

Export JSON

Essential information

Published
07/07/2025 13:55
Modified
13/07/2025 09:50
Tags
2025-07-07 batavia javav.exe multi-stage infection phishing spyware uac bypass vbs script webview.exe
Related entities
2 observables, 1 intrusion sets (apt), 16 techniques (mitre)

Description

The campaign, active since July 2024, targets Russian industrial enterprises through emails containing malicious links disguised as contract documents. The infection process involves three stages: a downloader, the , and the module. These components collect and exfiltrate various types of files, including system logs, office documents, and screenshots. The malware employs techniques to avoid duplicate file uploads and can download additional payloads. Over 100 users across dozens of organizations have been affected. The campaign highlights the importance of comprehensive cybersecurity measures and employee training to mitigate such threats.

External references