The threat actor known as GOFFEE has launched a series of targeted attacks against critical sectors within the Russian Federation, utilizing advanced malware and phishing techniques.
The group’s latest campaign involves the deployment of PowerModul, a PowerShell-based implant, to escalate their intrusion capabilities and carry out coordinated strikes effectively.
PowerModul has been identified as a pivotal component in GOFFEE’s latest arsenal, functioning as a downloader capable of fetching and executing additional malicious PowerShell scripts from its command and control (C2) server.
According to the Report, this evolution marks a strategic shift, as the group seeks to maintain persistence and evade detection more effectively.
Upon initial infection, PowerModul’s execution involves several steps:
The campaign has been particularly aggressive against:
Given the consistent victimology, the use of PowerTaskel, and the similar infection vectors observed in previous campaigns, security experts attribute these attacks to GOFFEE with high confidence.
The strategic deployment of PowerModul indicates GOFFEE’s intent to sustain long-term presence within targeted networks, potentially for espionage, sabotage, or data theft. Here are some defense strategies:
For organizations seeking more information or assistance with incident response, Kaspersky’s threat intelligence team is available at intelreports@kaspersky.com.
Find this News Interesting! Follow us on Google News, LinkedIn, & X to Get Instant Updates!
Whether you operate a small business or run a large enterprise, you rely on third-party…
Security researchers have revealed that two critical use-after-free (UAF) vulnerabilities in Google Chrome’s Browser process…
An alarming data leak involving Microsoft Defender XDR has exposed more than 1,700 sensitive documents…
Security researchers have uncovered a new and sophisticated threat to Microsoft Office 365 users: a…
A sophisticated cyberattack campaign has surfaced, targeting poorly managed Microsoft SQL (MS-SQL) servers to deploy…
The Zscaler ThreatLabz 2025 Phishing Report unveils the alarming sophistication of modern phishing attacks, driven…