Operation SkyCloak: Tor Campaign targets Military of Russia & Belarus
Oct. 31, 2025, 9:56 p.m.
Description
A sophisticated campaign targeting Russian and Belarusian military personnel has been identified, using multi-stage infection chains and decoy documents. The attackers deploy OpenSSH and Tor bridges to establish covert remote access and lateral movement capabilities. The infection process involves PowerShell scripts, scheduled tasks for persistence, and the use of Tor hidden services to expose multiple local services. The campaign employs anti-analysis techniques and leverages obfuscated configurations for SSH and Tor. While attribution remains uncertain, the targeting and tactics are consistent with Eastern European-linked espionage activities focusing on defense and government sectors.
Tags
Date
- Created: Oct. 31, 2025, 9:01 p.m.
- Published: Oct. 31, 2025, 9:01 p.m.
- Modified: Oct. 31, 2025, 9:56 p.m.
Indicators
- feae0baf291ff54a1366f0cd628665d2b1c9fe279ce2544d4f84c7aa46064f3c
- a939d1edcc422772124a373be68b7cb38110639db8b1f4b5dca0b7e94b8399e3
- a0eed0e1ef8fc4129f630e6f68c29c357c717df0fe352961e92e7f8c93e5371b
- 99ec6437f74eec19e33c1a0b4ac8826bcc44848f87cd1a1c2b379fae9df62de9
- 7946a2275c1c232eebed6ead95ea4723285950175586db1f95354b910b0a3cce
- 710e8c96875d6a3c1b4f08f4b2094c800658551065b20ef3fd450b210dcc7b9a
- 5d3a6340691840d1a87bfab543faec77b4a9d457991dd938834de820a99685f7
- 30a5df544f4a838f9c7ce34377ed2668e0ba22cc39d1e26b303781153808a2c4
- 08db5bb9812f49f9394fd724b9196c7dc2f61b5ba1644da65db95ab6e430c92b
- 77.20.116.133
- 142.189.114.119
- yuknkap4im65njr3tlprnpqwj4h7aal4hrn2tdieg75rpp6fx25hqbyd.onion
Additional Informations
- Defense
- Government
- Russian Federation