PROBABLYPWNED
Home/Tag/Russia

Russia

26 articles tagged with "Russia"

Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet
Threat Intelligence4 min read

Turla's Kazuar Backdoor Evolves Into Modular P2P Botnet

Microsoft exposes how Russia's FSB-linked Secret Blizzard transformed Kazuar from a monolithic backdoor into a three-module P2P botnet with advanced anti-detection capabilities.

Alex KowalskiMay 16, 2026
APT28's PRISMEX Malware Targets NATO Supply Chains
Threat Intelligence4 min read

APT28's PRISMEX Malware Targets NATO Supply Chains

Russian military hackers deployed PRISMEX steganography malware against Ukraine and NATO logistics networks, exploiting zero-days CVE-2026-21509 and CVE-2026-21513 weeks before patches.

Alex KowalskiApr 30, 2026
PhantomCore Exploits TrueConf Flaws to Breach Russian Networks
Threat Intelligence4 min read

PhantomCore Exploits TrueConf Flaws to Breach Russian Networks

Pro-Ukrainian hacktivist group PhantomCore chains three TrueConf vulnerabilities including CVSS 9.8 command injection to infiltrate Russian government and private organizations since September 2025.

Alex KowalskiApr 27, 2026
APT28 Uses BEARDSHELL and COVENANT to Spy on Ukraine
Threat Intelligence4 min read

APT28 Uses BEARDSHELL and COVENANT to Spy on Ukraine

Russian GRU-linked APT28 deploys BEARDSHELL and COVENANT implants for long-term surveillance of Ukrainian military personnel. ESET research reveals cloud storage abuse for C2.

Alex KowalskiMar 10, 2026
APT28 Linked to MSHTML Zero-Day Exploited Before Patch
Threat Intelligence4 min read

APT28 Linked to MSHTML Zero-Day Exploited Before Patch

Security researchers tie Russia's APT28 to CVE-2026-21513 exploitation using malicious LNK files. The MSHTML zero-day was weaponized weeks before Microsoft's February patch.

Alex KowalskiMar 3, 2026
APT28 Weaponized Office Zero-Day in Three Days Flat
Threat Intelligence3 min read

APT28 Weaponized Office Zero-Day in Three Days Flat

Operation Neusploit saw Russia's APT28 exploit CVE-2026-21509 against 60+ Ukrainian targets within 72 hours of Microsoft's disclosure, delivering MiniDoor and BEARDSHELL backdoors.

Alex KowalskiFeb 5, 2026