216.73.217.22

Restless Spirit: New Attacks on Russian Companies

· Published 23/01/2026 10:12 · Modified 23/01/2026 11:03

Export JSON

Essential information

Published
23/01/2026 10:12
Modified
23/01/2026 11:03
Tags
2026-01-23 command and control decoy documents multi-stage attack persistent threat phantomcore phantomcore.polldl phishing powershell russian targets scheduled tasks
Related entities
7 observables, 1 intrusion sets (apt), 7 techniques (mitre), 2 malware, 22 others

Description

, a hacking group targeting Russian and Belarusian companies since 2022, launched a new wave of malicious email campaigns on January 19 and 21, 2026. The attacks targeted various sectors including utilities, finance, urban infrastructure, aerospace, consumer digital services, chemical industry, construction, consumer goods manufacturing, and e-commerce. The campaign used emails with malicious attachments, leveraging compromised legitimate email addresses. The malware operates in multiple stages, including downloading , executing scripts, and establishing persistence through . The second stage malware, similar to previously known , communicates with servers to receive and execute commands.

External references