New Punishing Owl Hacker Group Targeting Networks of Russian Government Security Agency
A new hacktivist group, Punishing Owl, has been identified executing complex cyberattacks against Russian government security agencies.
A new hacktivist group, Punishing Owl, has been identified executing complex cyberattacks against Russian government security agencies.
The group first appeared on December 12, 2025, announcing a breach into a Russian government security agency's network. They subsequently published the stolen documents on a data leak site and a Mega.nz repository to maximize exposure.
Punishing Owl employed a variety of attack methods to enhance the impact of their operations. They accessed the victim's DNS configuration to create a subdomain and modify DNS records. Traffic was redirected to a server in Brazil hosting the stolen files and a political manifesto.
The group announced the breach on a Friday evening at 6:37 PM, a strategic choice aimed at delaying response efforts and increasing visibility.
A new hacktivist group, Punishing Owl, has been identified executing complex cyberattacks against Russian government security agencies.
Following the initial breach, Punishing Owl initiated business email compromise attacks against the victim's partners and contractors. They sent emails from a Brazilian server using addresses from the victim's email domain, falsely confirming the network compromise and requesting document reviews.
The attack infrastructure shows technical sophistication, including fake TLS certificates, IMAP and SMTP services for email operations, and the deployment of the ZipWhisper PowerShell stealer to extract browser credentials.
Infection Mechanism and Credential Theft
The ZipWhisper stealer uses a multi-stage infection process to capture sensitive browser data. When victims open a disguised LNK file, PowerShell commands execute, downloading the stealer payload. The malware collects and packages browser credentials, cookies, and passwords, which are then uploaded to the command-and-control server.
Analysis indicates the potential use of AI tools in developing portions of the malicious script, suggesting advanced development techniques may be employed to target Russian infrastructure.
Based on reporting by Cyber Security News.
