Full Report
A large-scale phishing campaign using DarkWatchman and Sheriff malware has been observed targeting companies in Russia and Ukraine
Analysis Summary
# Incident Report: Large-Scale Phishing Campaign Targeting Russia and Ukraine with DarkWatchman Malware
## Executive Summary
Between February 2022 and April 2025, the financially motivated threat group Hive0117 conducted large-scale, geographically focused phishing campaigns targeting organizations across Russia and Ukraine. The attacks utilized password-protected RAR archives delivered via email, deploying the fileless, JavaScript-based DarkWatchman Remote Access Trojan (RAT) to conduct keylogging and data collection. The ongoing nature of the threat highlights successful defense evasion techniques by the malware and the persistent targeting of critical sectors.
## Incident Details
- **Discovery Date:** April 29, 2025 (Latest observed wave)
- **Incident Date:** Active since at least February 2022 (Hive0117 activity noted)
- **Affected Organization:** Multiple companies across Russia and Ukraine.
- **Sector:** Media, tourism, finance, retail, manufacturing, energy, telecom, transport, and biotechnology.
- **Geography:** Russia and Ukraine (Previous activity also noted in Belarus, Lithuania, Estonia, and Kazakhstan).
## Timeline of Events
### Initial Access
- **Date/Time:** Observed wave on April 29, 2025. Attacks have been ongoing since at least February 2022.
- **Vector:** Large-scale email phishing campaigns targeting over 550 email addresses in the latest wave.
- **Details:** Emails contained password-protected RAR archives. Opening the archive deployed the malware payload.
### Lateral Movement
- *Details not specified in the summary, but DarkWatchman executes secondary payloads, implying capability for further network activities.*
### Data Exfiltration/Impact
- **Impact:** DarkWatchman malware performs keylogging and data collection. The specific data exfiltrated is not detailed, but the intention is financial motivation.
### Detection & Response
- **Detection:** Uncovered and analyzed by the Russian cybersecurity company F6 on April 29, 2025.
- **Response actions taken:** *Not explicitly detailed in the article, but analysis and reporting by F6 implies initial response activities.*
## Attack Methodology
- **Initial Access:** Phishing emails delivering password-protected RAR archives.
- **Persistence:** *Implied via RAT functionality, but specific mechanisms unknown.*
- **Privilege Escalation:** *Not detailed.*
- **Defense Evasion:** Current variant of DarkWatchman employs "enhanced evasion techniques" to bypass traditional detection systems.
- **Credential Access:** DarkWatchman performs keylogging.
- **Discovery:** *Implied via data collection capabilities.*
- **Lateral Movement:** *Implied via secondary payload execution, typical of RATs.*
- **Collection:** Keylogging and data collection activities performed by DarkWatchman.
- **Exfiltration:** *Methods not detailed.*
- **Impact:** Execution of secondary payloads and information theft for financial gain.
## Impact Assessment
- **Financial:** Hive0117 is noted as a financially motivated group.
- **Data Breach:** Sensitive data related to keylogging and data collection across critical sectors.
- **Operational:** Potential disruption due to execution of secondary payloads and compromise of business systems.
- **Reputational:** Targeting of numerous high-profile sectors suggests widespread impact.
## Indicators of Compromise
- **Network indicators (Defanged):** *None provided in the text.*
- **File indicators:** Updated variant of DarkWatchman RAT (JavaScript-based, fileless malware).
- **Behavioral indicators:** Keylogging, execution of secondary payloads, use of password-protected RAR archives as delivery mechanism.
## Response Actions
- **Containment measures:** *Not detailed.*
- **Eradication steps:** *Not detailed.*
- **Recovery actions:** *Not detailed.*
## Lessons Learned
- The threat group Hive0117 (active since Feb 2022) consistently targets Eastern European regions.
- Fileless malware (DarkWatchman) continues to evolve, successfully enhancing evasion tactics against established defenses.
- Password-protected archives remain a high-risk method for initial delivery in large-scale campaigns.
## Recommendations
- **Prevention measures for similar incidents:**
1. Implement advanced email filtering capable of spotting and scanning password-protected archive contents where feasible, or rigorously block common archive types.
2. Enhance monitoring specifically for fileless, JavaScript-based malware execution and keylogging activity.
3. Conduct regular specialized security awareness training focusing on recognizing sophisticated phishing attempts, particularly those utilizing password-protected attachments.