Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Massive offensive launched on Russian businesses

b90a7f17b5406db3ee17ec4bc82a704c6128b4ad8652776b4f55bc3948fa8385

TLP:CLEAR
Active

SHA-256 Hash

Description

In May and June 2026, the Clubfoot Wolf cluster executed a large-scale phishing campaign targeting Russian organizations across manufacturing, retail, e-commerce, agriculture, IT, transportation, healthcare, and science sectors, with primary focus on wholesale distributors of chemical products. Several Belarusian organizations were also compromised. The adversary sent phishing emails disguised as invoices or purchase requests, containing ZIP archives with decoy documents and malicious LNK files. Upon execution, a PowerShell script downloaded and installed NetSupport Manager, a legitimate remote administration tool, which was then used for malicious activities. The attackers employed URL shorteners to hide infrastructure and used multiple decoy files to build victim trust. The campaign demonstrated continuous evolution in delivery methods and infection chains.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Massive offensive launched on Russian businesses
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of b90a7f17b5406db3ee17ec4bc82a704c6128b4ad8652776b4f55bc3948fa8385

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.