HabrAugust 13, 2026🇷🇺Translated from Russian

Malinsure Cybercrime Group Deploys SafeMostSSH Backdoor via Phishing Lures Mimicking Russian Insurance Updates

Researchers from the F6 cyber-intelligence department have uncovered a new cybercrime cluster they track as Malinsure. The group uses phishing emails themed around voluntary medical insurance (DMS) to deliver a previously unknown backdoor named SafeMostSSH.

The campaign began surfacing in July 2026 when F6 analysts found samples uploaded from Russia to public sandboxes. The samples could not be attributed to any known malware family, prompting the creation of a new cluster designation derived from the insurance-themed lures.

Initial access relies on emails sent from addresses such as mutewinter78@gmail.com. The messages carry PDF attachments titled “ДМС обновления.pdf” or similar that instruct recipients to open a link leading to an RAR archive hosted on domains mimicking legitimate company file-sharing services.

Inside the archives are a renamed legitimate Microsoft executable (winword.exe or powerpnt.exe), a decoy document, and one or two DLLs. Execution triggers DLL Side-Loading of the malicious library, which then uses the LOLbin msiexec.exe with the command “msiexec.exe /Passive /Quiet -z” to invoke DllUnregisterServer and achieve persistence.

SafeMostSSH is a multi-stage backdoor that restores itself from a hidden backup, obtains new C2 addresses by parsing public posts on vc.ru, and establishes a reverse SSH tunnel to attacker infrastructure. The group has also experimented with HTML and SHTML files that embed base64- or hex-encoded payloads to drop the same archive components.

Observed lures reference Russian insurance firms, financial institutions, and fuel-energy companies. Infrastructure elements such as gosuslugi.email and minfin.support suggest a broad targeting scope within Russia.

Related articles

HabrMalware & Botnets

Engineer Tackles Jane Street ASIC Reverse Engineering Puzzle with Custom Simulator and Verilog Extraction

A detailed technical account describes how one engineer spent weeks reverse engineering an ASIC from GDS files provided in a Jane Street puzzle. The process began with parsing the GDS layout using the gdstk Python library to identify 27 cells in the warmup challenge and thousands of elements in the main task. The engineer built a custom logic simulator backed by SQLite, developed a domain-specific hardware description language, and eventually extracted a netlist that could be converted into Verilog for simulation. Key components identified included shift registers, an adder, and a comparator named comparitor496 in the warmup round. In the full challenge, nearly 10,000 instances of 81 different sky130 standard cells were processed, revealing an unexpected floating net that prompted a bug report to Jane Street. The effort combined manual schematic tracing, graph-based connectivity analysis, and waveform inspection with Surfer to confirm functional behavior.

BoletimSecMalware & Botnets

EtherHiding Campaign Hides Banking Trojan C2 in Polygon Smart Contracts

Security researchers have detailed the EtherHiding campaign, which conceals command-and-control infrastructure inside smart contracts on the Polygon blockchain. The final payload is a malicious browser extension that functions as a banking trojan, intercepting credentials and two-factor codes from approximately 479 financial and cryptocurrency websites. Instead of embedding fixed addresses in its code, the malware queries an encrypted C2 server address from the smart contract, allowing operators to change destinations through low-cost blockchain transactions that bypass domain blocking. Infection begins when victims visit one of 31 compromised legitimate sites that inject JavaScript displaying a fake CAPTCHA prompt. The prompt instructs users to press Windows+R and execute a PowerShell command, a social engineering technique known as ClickFix that downloads the malicious scripts without exploiting any software vulnerability. The campaign has remained active from November 2025 through at least September 2026, demonstrating the resilience of blockchain-based infrastructure against traditional takedown methods.

AntiMalwareMalware & Botnets

Group-IB Uncovers HEAVYGRAM Multi-Stage Windows Spyware Controlled via Telegram Bot API

Researchers at Group-IB have identified 29 new samples of HEAVYGRAM, a sophisticated multi-stage Windows malware designed to target journalists, Iranian dissidents, and government critics. The campaign begins with social engineering lures that deliver archives containing fake Telegram, KeePass, or video editor files, along with WSF, HTA, and Persian-language screensaver payloads. Once executed, the malware uses PowerShell to fetch additional components, establishes persistence through Windows startup mechanisms, and adds its directories to Microsoft Defender exclusions. The core implant, written in Python and packed with PyInstaller, supports DLL side-loading and communicates exclusively through Telegram Bot API to receive commands, capture screenshots, enumerate processes, and exfiltrate data. A particularly damaging capability allows theft of Telegram Desktop session files, enabling account hijacking without password re-entry. Group-IB attributes the operation to the Handala Hack group, linked to the Void Manticore persona also tracked as Storm-0842 and Red Sandstorm, believed to operate on behalf of Iranian intelligence services.

HabrMalware & Botnets

Kaspersky Details MovieReaper Malware Framework Distributed via Compromised Torrent Trackers

Kaspersky researchers have uncovered MovieReaper, a previously unknown modular malware framework that spreads through popular torrent sites by masquerading as movies, games, and other content. The campaign began after attackers compromised the itorrents repository in October 2025, allowing malicious torrents to propagate across multiple trackers and infect hundreds of users across Europe, Asia, and Africa. MovieReaper uses a multi-stage infection chain that includes a fake executable with a VLC icon, shellcode delivery from an initial C2, and a secondary C2 address retrieved from the Solana blockchain to improve resilience against takedowns. Subsequent stages bypass Windows UAC for persistence before deploying a final module with 21 commands for file system access, exfiltration, and potential additional payload deployment. The same report also covers NightEagle attacks on Russian infrastructure and the PAYLOAD extortion campaign using Active Directory Group Policy. Separate research highlights new side-channel attacks such as InjectEave on headphones and DDRop against Intel TDX and AMD SEV-SNP protections, along with a zero-day in Google Pixel radio modules and the arrest of TeamPCP members facilitated by Google Threat Intelligence Group.