AntiMalwareSeptember 3, 2026🇷🇺Translated from Russian

Buhtrap RAT Resurfaces in New Campaign Targeting Russian Accountants via Search Ads

Specialists from F6 have uncovered a new campaign distributing the Buhtrap RAT remote access trojan. The attackers continue their established tactic of targeting accountants and lawyers with counterfeit professional websites promoted through paid search engine advertisements.

The latest decoy closely replicates the legitimate resource Glavnaya Kniga Bukhgaltera. Visitors arrive seeking a required document and click the download button, only to receive a ZIP archive instead of a harmless file. JavaScript code on the page intercepts the request and dynamically generates a link to the malicious archive, whose filename incorporates the current date and time.

Inside the archive, victims find an executable such as Obrazets dokumenta pod indeksom 1.exe. Upon execution, Buhtrap RAT establishes persistence on the system and connects to the attackers’ command server. The trojan grants remote control over the compromised machine and is deployed in operations against Russian organizations.

Researchers at F6 noted that the infection chain has seen minimal changes compared with the previous campaign. The main update involves refreshed network infrastructure rather than new techniques. Buhtrap has been active since 2014 both as malware and as the name of the associated criminal group. Following the public release of its source code in 2016, the tool became available to various financially motivated threat actors.

Among the identified decoy domains are glavaudit.org, buhotchet.com, and audit24.org. Security experts recommend that users carefully verify website addresses and refrain from launching executable files that masquerade as documents.

Related articles

HabrMalware & Botnets

Engineer Tackles Jane Street ASIC Reverse Engineering Puzzle with Custom Simulator and Verilog Extraction

A detailed technical account describes how one engineer spent weeks reverse engineering an ASIC from GDS files provided in a Jane Street puzzle. The process began with parsing the GDS layout using the gdstk Python library to identify 27 cells in the warmup challenge and thousands of elements in the main task. The engineer built a custom logic simulator backed by SQLite, developed a domain-specific hardware description language, and eventually extracted a netlist that could be converted into Verilog for simulation. Key components identified included shift registers, an adder, and a comparator named comparitor496 in the warmup round. In the full challenge, nearly 10,000 instances of 81 different sky130 standard cells were processed, revealing an unexpected floating net that prompted a bug report to Jane Street. The effort combined manual schematic tracing, graph-based connectivity analysis, and waveform inspection with Surfer to confirm functional behavior.

BoletimSecMalware & Botnets

EtherHiding Campaign Hides Banking Trojan C2 in Polygon Smart Contracts

Security researchers have detailed the EtherHiding campaign, which conceals command-and-control infrastructure inside smart contracts on the Polygon blockchain. The final payload is a malicious browser extension that functions as a banking trojan, intercepting credentials and two-factor codes from approximately 479 financial and cryptocurrency websites. Instead of embedding fixed addresses in its code, the malware queries an encrypted C2 server address from the smart contract, allowing operators to change destinations through low-cost blockchain transactions that bypass domain blocking. Infection begins when victims visit one of 31 compromised legitimate sites that inject JavaScript displaying a fake CAPTCHA prompt. The prompt instructs users to press Windows+R and execute a PowerShell command, a social engineering technique known as ClickFix that downloads the malicious scripts without exploiting any software vulnerability. The campaign has remained active from November 2025 through at least September 2026, demonstrating the resilience of blockchain-based infrastructure against traditional takedown methods.

AntiMalwareMalware & Botnets

Group-IB Uncovers HEAVYGRAM Multi-Stage Windows Spyware Controlled via Telegram Bot API

Researchers at Group-IB have identified 29 new samples of HEAVYGRAM, a sophisticated multi-stage Windows malware designed to target journalists, Iranian dissidents, and government critics. The campaign begins with social engineering lures that deliver archives containing fake Telegram, KeePass, or video editor files, along with WSF, HTA, and Persian-language screensaver payloads. Once executed, the malware uses PowerShell to fetch additional components, establishes persistence through Windows startup mechanisms, and adds its directories to Microsoft Defender exclusions. The core implant, written in Python and packed with PyInstaller, supports DLL side-loading and communicates exclusively through Telegram Bot API to receive commands, capture screenshots, enumerate processes, and exfiltrate data. A particularly damaging capability allows theft of Telegram Desktop session files, enabling account hijacking without password re-entry. Group-IB attributes the operation to the Handala Hack group, linked to the Void Manticore persona also tracked as Storm-0842 and Red Sandstorm, believed to operate on behalf of Iranian intelligence services.

HabrMalware & Botnets

Kaspersky Details MovieReaper Malware Framework Distributed via Compromised Torrent Trackers

Kaspersky researchers have uncovered MovieReaper, a previously unknown modular malware framework that spreads through popular torrent sites by masquerading as movies, games, and other content. The campaign began after attackers compromised the itorrents repository in October 2025, allowing malicious torrents to propagate across multiple trackers and infect hundreds of users across Europe, Asia, and Africa. MovieReaper uses a multi-stage infection chain that includes a fake executable with a VLC icon, shellcode delivery from an initial C2, and a secondary C2 address retrieved from the Solana blockchain to improve resilience against takedowns. Subsequent stages bypass Windows UAC for persistence before deploying a final module with 21 commands for file system access, exfiltration, and potential additional payload deployment. The same report also covers NightEagle attacks on Russian infrastructure and the PAYLOAD extortion campaign using Active Directory Group Policy. Separate research highlights new side-channel attacks such as InjectEave on headphones and DDRop against Intel TDX and AMD SEV-SNP protections, along with a zero-day in Google Pixel radio modules and the arrest of TeamPCP members facilitated by Google Threat Intelligence Group.