Mercenary Akula Hits Ukraine-Supporting Financial...
A European financial institution involved in regional development and reconstruction initiatives was targeted by a social engineering attack attributed to the Russia-aligned Mercenary Akula. The attack used a spoofed Ukrainian judicial domain to deliver an email containing a link to a remote access payload. The target was a senior legal and policy advisor involved in procurement. The attack employed a multi-stage extraction process and deployed the Remote Manipulator System, a legitimate remote administration tool. This incident suggests the adversary may be expanding beyond primarily Ukraine-based targeting, potentially probing Ukraine-supporting institutions in Western Europe. The attack aligns with Mercenary Akula's established tactics, including localized social engineering, multi-stage payload delivery, and the use of signed remote administration tools.
Pulse ID: 699ede794dd30674f7d583d5
Pulse Link: https://otx.alienvault.com/pulse/699ede794dd30674f7d583d5
Pulse Author: AlienVault
Created: 2026-02-25 11:35:21
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CyberSecurity #Email #Europe #ICS #InfoSec #OTX #OpenThreatExchange #RAT #RCE #Russia #SocialEngineering #UK #Ukr #Ukraine #Ukrainian #WesternEurope #bot #AlienVault