New “Punishing Owl” Hacker Group Targets Networks Linked to Russian Security Agency
A newly identified threat actor, known as Punishing Owl, has breached a Russian government security agency, indicating the emergence of a politically motivated hacktivist group. The attack showcased advanced operational security measures that surpass…
A newly identified threat actor, known as Punishing Owl, has breached a Russian government security agency, indicating the emergence of a politically motivated hacktivist group. The attack showcased advanced operational security measures that surpass standard data exfiltration approaches.
On the same day of the breach announcement, Punishing Owl utilized administrative access to the compromised DNS infrastructure, creating a subdomain that redirected users to their servers in Brazil. They configured legitimate-looking TLS certificates and established IMAP and SMTP services to replicate the victim's infrastructure, facilitating credential harvesting and social engineering.
On December 12, 2025, the group published evidence of the intrusion, including internal documents, on a DLS website and mirrored these on Mega.nz repositories. The timing of the disclosure, Friday at 6:37 PM, seems strategically chosen to minimize response time from Russian security services while maximizing public exposure.
Following the initial breach, Punishing Owl initiated a coordinated email campaign targeting the victim's business partners and contractors. Emails purportedly from the organization and later from the victim's employees were sent from the Brazilian infrastructure, directing recipients to the modified DNS records and prompting them to open password-protected archives.
The ZIP files contained LNK files disguised as PDFs using double-extension obfuscation. Upon execution, these files executed PowerShell commands to download ZipWhisper, a custom stealer designed to extract web browser data, credentials, and cached authentication tokens. The stolen data was packaged into ZIP archives and uploaded to command-and-control servers via HTTP POST requests.
The group's C2 domain, bloggoversikten[.]com (82.221.100[.]40), impersonated a Russian-language technical blog, which was legitimately operated until 2015 and dormant until re-registered in 2025. Analysis of the stealer code suggested AI-assisted code generation, indicating that the group may lack extensive malware development expertise but has access to modern development tools.
Punishing Owl's activities primarily target Russian critical infrastructure, including government agencies, research institutions, and IT organizations. Multiple social media and darknet marketplace accounts were registered in December 2025, suggesting deliberate brand establishment. Geolocation data suggests administration from Kazakhstan, though this requires further verification.
The attack showcased advanced operational security measures that surpass standard data exfiltration approaches.
Security researchers observe that Punishing Owl exemplifies a trend of politically motivated hacktivist collectives amid rising geopolitical tensions. The group's advanced tradecraft, custom malware development, and sustained infrastructure investment indicate that this campaign is more than a one-off action. Monitoring the group's activities remains critical for organizations in the Russian threat landscape.
Category MD5 SHA1 SHA256
ZIP Archive 99ed9a3126f72ec70975a3d6246130e0 85a8d1b54b294a01089948573fce7c0059b8b2b1 94b93f4540f01956895a74d2c0b54e502f2be299e4d2ea0a3cc639619377f229
LNK Loader #1 b72c550737ef4fbf74b529d1a1b33569 d10818d99a616720f6d061b95659d34bbc575821 37f307b378c028afa67a236a05224e367ed486ab3ab2f7c3e13518d0823e137d
LNK Loader #2 bbf0b95372c89eada433b41eeef5f761 64f1a24f2f81632329e84a30b15ca8a74b5478c3 dfd49ea1911fb7e800440c82b6518828ec7fa7c595d7ea6baabec29e5d9cecec
ZipWhisper Styler #1 07807a7da277184539e35126f1ab3bae d24e8f21cbe4dcd573aaa914c41df8609c5d3f47 09636fbca343f268ee7c0c033e37a9b007fe40ce914c4273ed961d84b52bed17
ZipWhisper Styler #2 5db00ab3e6875c14cf550b1e7c664310 83fdfe08206a05c85833873576653d0802883d9e b1782f8f3440ce4b184f27c4047439aa998058ec17319a5b08031eda545d5a50
ZipWhisper Styler #3 8027ca72007f5b4a270ab8230c7b5bf5 a82eb95e60f084c261f88d60aff1cee30602552f f25506f5a7f3580edae159bbdbca3f8d17dfeeaadcc548c8202a764399550778
ZipWhisper Styler #4 33c78c7126ae56040f04de4df4139acb 8deffa9765915a57e9679f4481dac43dabbbcecd 6aa09062a755775e1b11dfd5fa80981fa50e1ecf4ba3f1ae41b2ed8b671e0f6a
Based on reporting by GBHackers.
