Cybercriminals Target Russian Troops with Fake Dating Profiles for Espionage

Cybercriminals Target Russian Troops with Fake Dating Profiles for Espionage

2d ago Therecord.MediaEscudodigital 77% similarity 70.5
Share:

Article Content

Browse articles
ThreatCluster

A cyberespionage group named 'SiribClone' has been targeting Russian military personnel since summer 2025. This group uses social engineering tactics, posing as women seeking romantic relationships to compromise soldiers' mobile phones and Telegram accounts. The attackers aim to gather sensitive military intelligence by persuading victims to download malicious applications or enter credentials on phishing sites. The malware, identified as 'SafeLoveStealer,' can steal personal data and provide remote access to infected devices. The campaign was detected in early 2026, with a resurgence in May linked to Victory Day celebrations. Researchers from the Russian cybersecurity firm F6 have documented this threat, highlighting its focus on troops in border regions and combat zones. The group employs various deceptive tactics, including fake humanitarian aid offers and requests for intimate photos.

Key Points: • The cyberespionage group 'SiribClone' targets Russian soldiers using fake dating profiles. • Malware 'SafeLoveStealer' is designed to steal sensitive data and provide remote access. • The campaign has been active since summer 2025, with renewed activity noted in May 2026.

ThreatCluster AI

Timeline

2025-06-01
SiribClone begins operations
The cyberespionage group starts targeting Russian military personnel using social engineering tactics.
Therecord.Media
2026-01-01
Malicious ZIP files sent to military personnel
Military personnel receive ZIP files disguised as military documents, marking the start of detected attacks.
Escudodigital
2026-05-01
Campaign resurgence linked to Victory Day
SiribClone resumes operations with new malware distributed through themed pages for Victory Day celebrations.
Escudodigital
2026-06-09
Details of SiribClone's tactics published
The Record Media reports on the group's use of fake dating profiles to target Russian soldiers.
Therecord.Media
2026-06-12
Escudodigital reports on malware 'SafeLoveStealer'
Escudodigital reveals the capabilities of the malware used by SiribClone to steal sensitive data.
Escudodigital

Community

Browse all →