Stealth Predators: DarkWatchman and Sheriff Malware Unleash Nation-Grade Tactics Across Russia and Ukraine


# Russian Companies Targeted in Large-Scale DarkWatchman Malware Campaign

A sophisticated phishing campaign has been targeting Russian companies across multiple sectors, delivering the DarkWatchman malware, according to cybersecurity firm F6. The attacks have affected organizations in media, tourism, finance, insurance, manufacturing, retail, energy, telecom, transport, and biotechnology.

Security researchers attribute this campaign to a financially motivated threat group known as Hive0117, which has previously targeted users in Lithuania, Estonia, and Russia. The group has been particularly active since 2023, with campaigns in September targeting energy and finance sectors across Russia, Kazakhstan, Latvia, and Estonia, followed by November attacks using courier delivery-themed lures.

DarkWatchman, first documented in December 2021, is a JavaScript-based remote access trojan capable of keylogging, collecting system information, and deploying secondary payloads. Its fileless nature and ability to remove traces of its existence demonstrate sophisticated capabilities. The latest attacks use password-protected archives to deliver an improved variant designed to evade detection.

## Ukraine’s Defense Sector Targeted by New Sheriff Backdoor

In a separate development, IBM X-Force reported that Ukraine’s defense sector was targeted in early 2024 with a previously undocumented Windows backdoor called Sheriff. The threat actor used Ukraine’s popular news portal, ukr.net, likely compromised in March 2024, to host the malware.

Sheriff is a modular backdoor that can execute commands, capture screenshots, and exfiltrate data using Dropbox’s cloud storage API. It includes a “suicide” function that, when activated remotely, terminates all activity and deletes all traces of the malware.

Researchers noted similarities between Sheriff and malware used by other threat actors, including Turla’s Kazuar and Crutch, Operation Groundbait’s Prikormka, and Bad Magic’s CloudWizard.

## Rising Cyber Incidents in Ukraine

Ukraine’s State Service for Special Communications and Information Protection reported a 48% increase in cyber incidents in the second half of 2024 compared to the first half. The total number of incidents in 2024 reached 4,315, continuing an upward trend from previous years, though critical and high-severity incidents decreased significantly.

According to Ukrainian authorities, Russian hackers are increasingly using automation, supply chain attacks, and combined espionage and sabotage techniques, with a primary focus on gathering intelligence that could impact front-line operations.

Share This Article