Skip to content
Amnesia RAT and Ransomware Target Russian Users in Phishing Campaign

Amnesia RAT and Ransomware Target Russian Users in Phishing Campaign

First seen 27 Jan 2026, 01:44 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster March 12, 2026 at 13:27 UTC

A multi-stage phishing campaign is targeting Russian organizations with Amnesia RAT and Hakuna Matata ransomware. The attackers use social engineering tactics to deliver malicious files disguised as business documents, exploiting Microsoft Windows features for infection. The campaign employs a complex infection chain that includes a PowerShell script for persistence.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 182d ago How this analysis works

More articles in this cluster (2)

Following this threat?

Track Hakuna Matata and Amnesia RAT in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed