Threat actors target Russian businesses with new malware
Between July and September 2026, BI.ZONE Threat Intelligence researchers observed mass phishing campaigns targeting organizations across various economic sectors—from agriculture, energy, and logistics to IT and construction. A key feature of these campaigns is the use of the trojan LxBase RAT, which had not previously been observed in attacks against Russian companies.
Distributed under the MaaS model, the malware is relatively inexpensive: a subscription costs just $119 per month and provides access to a fully functional trojan alongside a specialized crypter for bypassing security controls. This enables even less experienced threat actors to leverage a ready‑made suite of tools for stealthy attacks.
The malware is delivered via social engineering: phishing emails are crafted to mimic internal business correspondence, specifically communications with counterparties in Kazakhstan. The messages contain malicious archives disguised as internal orders or requests for price quotes, increasing the likelihood that the recipient will open the attachment.
These attacks use a sophisticated, multistage malware delivery architecture. The process begins when a user receives a RAR archive disguised as a standard document containing obfuscated JavaScript loaders. Upon execution, the JavaScript file drops the next‑stage components onto the disk: a PowerShell loader, two encrypted and encoded payload files, and VBS/Batch scripts to execute the PowerShell payload.
During the next stage, a .NET assembly DLL is executed—a specialized file that allows malicious code to run within other programs. In the final stage, the LxBase RAT payload is injected directly into the legitimate MSBuild.exe process. This technique enables threat actors to make malicious activity appear to originate from a trusted Windows component, significantly hindering detection by traditional security solutions.
Successful prevention of such attacks relies heavily on the effectiveness of perimeter defenses, particularly the ability of email security solutions to detect phishing messages. However, given the multistage nature of the attack chain, organizations must not rely solely on this class of tools. Continuous infrastructure monitoring and the integration of up‑to‑date threat intelligence provide an additional layer of protection, enabling organizations to detect and contain compromises at an early stage, even if the primary defense is bypassed.
The BI.ZONE Threat Intelligence portal provides timely access to the latest indicators of compromise, alongside detailed data on threat actor tactics and toolkits. This intelligence empowers security teams to respond to incidents faster and build robust defenses tailored to the most relevant threats facing their organization.