Attacks spreading the Remcos RAT malware have been launched by Russian state-backed cyberespionage operation Gamaredon against Ukraine as part of a phishing campaign that has been underway since November, reports Security Affairs.
Gamaredon, also known as ACTINIUM, Armageddon, Callisto, and Primitive Bear, distributes phishing emails using troop-related lures that include malicious LNK files containing PowerShell code, which facilitates second-stage payload and decoy file deployment to evade detection, according to an analysis from Cisco Talos. Extraction of the payload to the %TEMP% folder is then followed by side-loading of another DLL that loads, decrypts, and executes Remcos RAT. Further analysis of Gamaredon's PowerShell scripts indicates legitimate app exploitation and the utilization of clean and malicious files, said Cisco Talos researchers. "We can see in the previously mentioned sample downloaded by "Any.run" that it contains the clean application TivoDiag.exe, as well as two DLLs. The file "mindclient.dll" is the malicious DLL which is loaded by "TivoDiag.exe" during execution," the report noted.
Security researchers at Group-IB have identified multiple scam campaigns targeting fans eager to purchase tickets for Celine Dion's return to the stage.
The campaign, active since at least January 2026, employs rotating lures tied to the calendar, such as tax themes in winter and Valentine's or Easter invitations later on, according to Forescout.
The platform, active since 2020, allowed criminals to make over 1.8 million scam calls globally, targeting approximately 170,000 victims and causing tens of millions in financial losses.
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news