New Hacking Group “ComicForm” Strikes Eurasian Industries with Sophisticated PDF-Disguised Malware Campaign

# New Cyber Threats Target Eastern Europe and South Korea with Advanced Phishing Campaigns

## ComicForm Group Launches Multi-Stage Attacks Across Three Nations

A newly discovered hacking group called ComicForm has been conducting sophisticated phishing campaigns against organizations in Belarus, Kazakhstan, and Russia since April 2025. The group has primarily focused on industrial, financial, tourism, biotechnology, research, and trade sectors, according to cybersecurity firm F6.

### Attack Method and Tactics

The ComicForm group employs a multi-layered approach to infiltrate target systems:

**Initial Contact**: Attackers send convincing phishing emails with subject lines such as “Waiting for the signed document,” “Invoice for Payment,” or “Reconciliation Act for Signature.” These messages, written in Russian or English, originate from email addresses using .ru, .by, and .kz domains.

**Malware Delivery**: Recipients are prompted to open RAR archives containing Windows executables disguised as PDF documents (example: “Акт_сверки pdf 010.exe”). Once executed, these files launch a complex three-stage payload system.

**Evasion Techniques**: The malware creates scheduled tasks and configures Microsoft Defender exclusions to avoid detection. Interestingly, the code contains harmless Tumblr links to comic superhero GIFs, which gave the group its name but serve no malicious purpose.

### Credential Harvesting Operations

Beyond malware distribution, ComicForm has also deployed credential-stealing campaigns. These attacks redirect victims to fake login pages that mimic legitimate document management services. The sophisticated phishing pages use JavaScript to extract email addresses and dynamically generate backgrounds using screenshots of the victim’s domain.

## SectorJ149 Targets South Korean Industries

Separately, cybersecurity researchers have identified another threat group, SectorJ149 (also known as UAC-0050), conducting pro-Russian attacks against South Korean manufacturing, energy, and semiconductor companies.

### Attack Characteristics

The group uses spear-phishing emails targeting executives with business-themed lures about facility purchases or quotation requests. Their attack chain involves:

– Visual Basic Scripts distributed through Microsoft cabinet archives
– PowerShell commands that fetch malicious payloads from GitHub or Bitbucket
– Deployment of commodity malware including Lumma Stealer, Formbook, and Remcos RAT

### Shifting Motivations

While SectorJ149 previously operated primarily for financial gain, recent activities suggest a shift toward hacktivist objectives, using cyber attacks to convey political and ideological messages.

## Key Takeaways

Both campaigns demonstrate the evolving sophistication of cyber threats targeting specific regions and industries. Organizations should implement robust email security measures, employee training programs, and multi-layered defense strategies to protect against these advanced persistent threats. The use of legitimate platforms like GitHub and Bitbucket for malware hosting highlights the need for comprehensive security monitoring across all digital channels.

Share This Article