By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > Computing > Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
Computing

Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs

News Room
Last updated: 2026/02/13 at 1:30 PM
News Room Published 13 February 2026
Share
Google Ties Suspected Russian Actor to CANFAIL Malware Attacks on Ukrainian Orgs
SHARE

Ravie LakshmananFeb 13, 2026Threat Intelligence / Malware

A previously undocumented threat actor has been attributed to attacks targeting Ukrainian organizations with malware known as CANFAIL.

Google Threat Intelligence Group (GTIG) described the hack group as possibly affiliated with Russian intelligence services. The threat actor is assessed to have targeted defense, military, government, and energy organizations within the Ukrainian regional and national governments.

However, the group has also exhibited growing interest in aerospace organizations, manufacturing companies with military and drone ties, nuclear and chemical research organizations, and international organizations involved in conflict monitoring and humanitarian aid in Ukraine, GTIG added.

“Despite being less sophisticated and resourced than other Russian threat groups, this actor recently began to overcome some technical limitations using LLMs [large language models],” GTIG said.

“Through prompting, they conduct reconnaissance, create lures for social engineering, and seek answers to basic technical questions for post-compromise activity and C2 infrastructure setup.”

Recent phishing campaigns have involved the threat actor impersonating legitimate national and local Ukrainian energy organizations to obtain unauthorized access to organizational and personal email accounts.

The group is also said to have masqueraded as a Romanian energy company that works with customers in Ukraine, in addition to targeting a Romanian firm and conducting reconnaissance on Moldovan organizations.

To enable its operations, the threat actor generates email address lists tailored to specific regions and industries based on their research. The attack chains seemingly contain LLM-generated lures and embed Google Drive links pointing to a RAR archive containing CANFAIL malware.

Typically disguised with a double extension to pass off as a PDF document (*.pdf.js), CANFAIL is an obfuscated JavaScript malware that’s designed to execute a PowerShell script that, in turn, downloads and executes a memory-only PowerShell dropper. In parallel, it displays a fake “error” message to the victim.

Google said the threat actor is also linked to a campaign called PhantomCaptcha that was disclosed by SentinelOne SentinelLABS in October 2025 as targeting organizations associated with Ukraine’s war relief efforts through phishing emails that direct recipients to fake pages hosting ClickFix-style instructions to activate the infection sequence and deliver a WebSocket-based trojan.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article Days After Its Super Bowl Ad, Ring Cancels Flock Partnership Amid Surveillance Concerns Days After Its Super Bowl Ad, Ring Cancels Flock Partnership Amid Surveillance Concerns
Next Article Meta could soon bring facial recognition to its smart glasses — what could go wrong? Meta could soon bring facial recognition to its smart glasses — what could go wrong?
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

4chan’s creator says ‘Epstein had nothing to do’ with creating infamous far-right board /pol/
4chan’s creator says ‘Epstein had nothing to do’ with creating infamous far-right board /pol/
News
YouTube TV vs. Fubo vs. Hulu Live vs. Sling and More: 100 Top Live TV Streaming Channels Compared
YouTube TV vs. Fubo vs. Hulu Live vs. Sling and More: 100 Top Live TV Streaming Channels Compared
News
RFK Jr. calls Carbon Robotics’ laser weed zapper the ‘light at the end of the tunnel’ in herbicide fight
RFK Jr. calls Carbon Robotics’ laser weed zapper the ‘light at the end of the tunnel’ in herbicide fight
Computing
‘It’s over for us’: release of new AI video generator Seedance 2.0 spooks Hollywood
‘It’s over for us’: release of new AI video generator Seedance 2.0 spooks Hollywood
News

You Might also Like

RFK Jr. calls Carbon Robotics’ laser weed zapper the ‘light at the end of the tunnel’ in herbicide fight
Computing

RFK Jr. calls Carbon Robotics’ laser weed zapper the ‘light at the end of the tunnel’ in herbicide fight

6 Min Read
GNOME 50 Beta Released With Stable VRR, GDM Improvements
Computing

GNOME 50 Beta Released With Stable VRR, GDM Improvements

1 Min Read
Apple to continue partnership with Baidu, collaborate with Alibaba on AI for iPhone · TechNode
Computing

Apple to continue partnership with Baidu, collaborate with Alibaba on AI for iPhone · TechNode

1 Min Read
How to Master Amazon Affiliate Marketing
Computing

How to Master Amazon Affiliate Marketing

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?