Russian state-sponsored APT
Unknown Active
- Mentions
- 4
- First seen
- 09 Jun 2026
- Last seen
- 11 Sept 2026
Relevant to you · Relevant
- Threat focus:
- espionage / apt
- Sector / region:
- ManufacturingDACH
Origin
Unattributed
Profile
Russian state-sponsored APT actors are reportedly increasingly using AI tools like Claude AI to automate malware evasion. They target network devices and routers, with officials again warning about this threat. Additionally, a WinRAR vulnerability is being exploited against Ukrainian organizations. The attacks particularly affect Ukraine and critical network infrastructure.
Affected vendors
RarlabAnthropic
Targeted sectors
network infrastructure
Targeted regions
Eastern Europe
Targeted countries
UAUkraine
Linked CVEs
- CVE-2025-8088 KEV CVSS 8.8 EPSS 12%
Related actors
Share a CVE, technique or malware with this actor.
Activity (8 weeks)
Recent activity
- Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion SecurityWeek
- Improve Router Hygiene to Protect Against Russian State-Sponsored Targeting CISA Advisory
- Officials once again warn defenders that Russian hackers are targeting network devices CyberScoop
- Russian Attackers Weaponize WinRAR Flaw Against Ukrainian Orgs darkreading