Inside a Multi-Stage Windows Malware Campaign

Jan. 20, 2026, 7:15 p.m.

Description

A sophisticated multi-stage malware campaign targeting Windows users in Russia has been identified. The attack chain begins with social engineering lures and progresses to a full system compromise, including security bypass, surveillance, and ransomware delivery. It abuses Defendnot to disable Microsoft Defender and uses modular hosting across cloud services. The attack employs various techniques such as PowerShell scripts, obfuscated VBScript, and COM object manipulation. It deploys Amnesia RAT for data theft and surveillance, Hakuna Matata ransomware for file encryption, and a WinLocker component for system lockout. The campaign demonstrates how full system compromise can be achieved without exploiting software vulnerabilities, instead relying on social engineering and abuse of legitimate Windows features.

Date

  • Created: Jan. 20, 2026, 5:50 p.m.
  • Published: Jan. 20, 2026, 5:50 p.m.
  • Modified: Jan. 20, 2026, 7:15 p.m.

Indicators

  • e6ca6bab85ae1eff08a59b46b7905ae0568110da172dec8367f32779094bdd08
  • 5443232a367a83ac2899b37c066dae3ec2010df292291db24ce3d744133218a6
  • 359fe8df31c903153667fbe93795929ad6172540b3ee7f9eff4bcc1da6d08478
  • 7de56603a7b41fca9313231df6105dbb8148d3b0d80dfbc00e71e1d88f871915
  • 1828614be6d9bdd92f7ee30e12c8aac8eba33a6df2c92995f9bf930c3f1b992b
  • 45e942ba59f3876b263a03ed7e5d5b1b250e84a0a4b4093b3c13b5fca4e12b21
  • 71069a5d2a80a047ca36ca82e630d353829726d4f03a74c7522b7700c5c2bb59
  • 6222775b877b4be4f5407525d52c5889739b96c302e5a204ef369b4a51c6dab2
  • 3aa6ebb73390d304eef8fd897994906c05f3e967f8f6f6a7904c6156cf8819f9
  • 263b5ba921e478215dc9e3a397157badab415fc775cfb4681821b7446c14fb1a
  • 7b8cf0ef390a7d6126c5e7bf835af5c5ce32c70c0d58ca4ddc9c238b2d3f059a

Additional Informations

  • Russian Federation