Mercenary Akula Hits Ukraine-Supporting Financial...

Feb. 25, 2026, 11:55 a.m.

Description

A European financial institution involved in regional development and reconstruction initiatives was targeted by a social engineering attack attributed to the Russia-aligned Mercenary Akula. The attack used a spoofed Ukrainian judicial domain to deliver an email containing a link to a remote access payload. The target was a senior legal and policy advisor involved in procurement. The attack employed a multi-stage extraction process and deployed the Remote Manipulator System, a legitimate remote administration tool. This incident suggests the adversary may be expanding beyond primarily Ukraine-based targeting, potentially probing Ukraine-supporting institutions in Western Europe. The attack aligns with Mercenary Akula's established tactics, including localized social engineering, multi-stage payload delivery, and the use of signed remote administration tools.

Date

  • Created: Feb. 25, 2026, 11:35 a.m.
  • Published: Feb. 25, 2026, 11:35 a.m.
  • Modified: Feb. 25, 2026, 11:55 a.m.

Indicators

  • 42de03e314c4c9fd69cb042833e8d25950b0a842c28e9b2e18f363c843a9d283
  • 4f20691c7890e20af642763d030c608a96a84182e44c902aaa89d4f1394dac0a
  • f5ab8640a0ae68f25dcd0a7461266a46322f01a790fec8dafe7ec32a535e5d8e
  • 690ee1907bfb425a791e255eabe7351903e8a9e92089a099997afa2a8070383b
  • d9e1a79bd2aef55b73b9d4cbc7983a77f918ea6fc344ab9c59e35bc8afaaff6f
  • 761d4add56e0766e7e6314950d5cf4ebf759d43c75e74375c2a65f29040dd6fd
  • cd652cb4dcbc0c077bc4772fde6e7654be399517879201b820147abb58d2b9bd
  • 9b61bb9374de332fd80909f30d102043befcd569d264715b0a4d5d5a8d0762d3
  • 3d99abebdc72cd840ff42b3a5b4cf6e8e3a50616881097d0ceb058f87d2b3909
  • 28926919956c3e3f281f504c45dfe3419d4f37683806f76393f2a7c6d6e1abfa

Attack Patterns

  • QuasarRAT
  • Remote Manipulator System
  • Remcos
  • Mercenary Akula

Additional Informations

  • Finance
  • Government
  • Romania
  • Ukraine