[ << ALL_FEED ]

PrevedNetMedved

More in General

PrevedNetMedved 🐻

In October 2025, our cyber intelligence team detected ongoing phishing activity by a hacker group we have designated as NetMedved. The attacks targeted Russian organizations: victims received ZIP archives containing a set of decoy documents mimicking the document flow of Russian companies, as well as disguised LNK files that initiated the download of the next stage and deployment of NetSupportRAT on victims’ devices.

The malware operators used multiple attack vectors — ranging from more classic chains involving PowerShell scripts and HTA files to a significantly rarer technique: delivering malicious code via the Finger protocol and subsequently executing it in the command line.

After analyzing the activity and network infrastructure of NetMedved, we observed consistent overlaps with the December 2024 campaign against Russian companies, which we previously covered in a post titled “PrevedMedved 👋 — It’s Lumma Stealer Again.”

Details of the attack, analysis of the TTPs used, and the rationale behind the group’s naming — in our blog on Habr.

#TI #APT #Phishing
@ptescalator

More from ti_author

More from ti_author

More in General