Mercenary Akula Hits Ukraine-Supporting Financial...
Feb. 25, 2026, 11:55 a.m.
Description
A European financial institution involved in regional development and reconstruction initiatives was targeted by a social engineering attack attributed to the Russia-aligned Mercenary Akula. The attack used a spoofed Ukrainian judicial domain to deliver an email containing a link to a remote access payload. The target was a senior legal and policy advisor involved in procurement. The attack employed a multi-stage extraction process and deployed the Remote Manipulator System, a legitimate remote administration tool. This incident suggests the adversary may be expanding beyond primarily Ukraine-based targeting, potentially probing Ukraine-supporting institutions in Western Europe. The attack aligns with Mercenary Akula's established tactics, including localized social engineering, multi-stage payload delivery, and the use of signed remote administration tools.
Tags
Date
- Created: Feb. 25, 2026, 11:35 a.m.
- Published: Feb. 25, 2026, 11:35 a.m.
- Modified: Feb. 25, 2026, 11:55 a.m.
Indicators
- 42de03e314c4c9fd69cb042833e8d25950b0a842c28e9b2e18f363c843a9d283
- 4f20691c7890e20af642763d030c608a96a84182e44c902aaa89d4f1394dac0a
- f5ab8640a0ae68f25dcd0a7461266a46322f01a790fec8dafe7ec32a535e5d8e
- 690ee1907bfb425a791e255eabe7351903e8a9e92089a099997afa2a8070383b
- d9e1a79bd2aef55b73b9d4cbc7983a77f918ea6fc344ab9c59e35bc8afaaff6f
- 761d4add56e0766e7e6314950d5cf4ebf759d43c75e74375c2a65f29040dd6fd
- cd652cb4dcbc0c077bc4772fde6e7654be399517879201b820147abb58d2b9bd
- 9b61bb9374de332fd80909f30d102043befcd569d264715b0a4d5d5a8d0762d3
- 3d99abebdc72cd840ff42b3a5b4cf6e8e3a50616881097d0ceb058f87d2b3909
- 28926919956c3e3f281f504c45dfe3419d4f37683806f76393f2a7c6d6e1abfa
Additional Informations
- Finance
- Government
- Romania
- Ukraine