Russia

Winsage
August 14, 2026
CoolClient is a sophisticated backdoor family linked to the HoneyMyte APT group, actively used in cyber-espionage campaigns targeting organizations in Asia and Russia since its initial disclosure in 2022. It has capabilities such as keylogging, clipboard theft, credential harvesting, and system reconnaissance. Investigations in 2023 revealed enhancements, including clipboard theft and HTTP traffic interception. By late 2025 and into 2026, a variant was noted that could deploy a signed kernel-mode driver as a Windows service, improving its stealth and operational capabilities. In a recent campaign targeting Myanmar, the HoneyMyte group used PlugX to deploy CoolClient components. They configured Microsoft Defender to exclude a fake Windows Defender installation directory and a renamed executable, defender.exe, to avoid detection. Persistence was achieved through a scheduled task that executed defender.exe with SYSTEM privileges at startup, which sideloaded the malicious libngs.dll to initiate the CoolClient execution chain. The latest CoolClient variant has a multi-stage execution chain, including: - defender.exe / Sang.exe: Exploited legitimate application for DLL sideloading. - libsrapc.dll: Benign dependency for the Sangfor application. - libngs.dll: First-stage loader that decrypts and loads the next stage. - loadcert.ini: Second-stage DLL implementing core functionalities. - cert.ini: Final-stage implant for command and control communication. - time.ini: Configuration file for CoolClient. The execution begins with the legitimate Sangfor application loading libngs.dll, which uses obfuscation to conceal its operations. The second stage, loadcert.ini, is injected into synchost.exe and performs tasks including persistence and process injection. The kernel-mode driver deployment routine involves decrypting time.ini, verifying privileges, and creating a service to execute the driver, enhancing stealth. The deployed kernel-mode driver, msagent.sys, is digitally signed and helps hide processes, files, and registry objects, making detection more difficult. The latest variant continues to target organizations consistent with previous HoneyMyte activities, with confirmed victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. The deployment of CoolClient as a secondary backdoor after a PlugX infection indicates a strategic approach to maintain access to compromised systems. The malware is confirmed as a new variant of CoolClient associated with the HoneyMyte threat group, with the kernel-mode driver marking a significant advancement in its capabilities.
AppWizard
August 12, 2026
Russian authorities have charged Pavel Durov, the founder and CEO of Telegram, with aiding terrorism and placed him on an international wanted list. The Federal Security Service (FSB) alleges that Telegram facilitates criminal activities and operations related to Ukrainian intelligence, classifying it as a facilitator of "acts of sabotage and terrorism, mass murder, and cyber fraud." Instead of targeting the platform with fines or restrictions, Russian authorities are pursuing Durov personally. If convicted in Russia, he faces the possibility of life imprisonment. This case reflects a broader trend of governments holding technology executives accountable for content and activities on their platforms, with similar legal pressures observed on other platforms like Meta, TikTok, Snap, and YouTube.
AppWizard
August 12, 2026
Apple has reinstated Telegram to its App Store after a temporary removal due to the discovery of child sexual abuse material. Telegram responded by removing the offending content and banning the user responsible, which helped recover the value of the Gram token that had initially dipped by approximately 6.4%. The incident underscores the scrutiny messaging platforms face regarding illegal content, with Telegram currently under scrutiny in Russia, France, and Australia for alleged facilitation of illegal activities and extremist content.
AppWizard
August 6, 2026
Ubisoft is offering the PC version of Ghost Recon: Future Soldier for free through the Ubisoft Connect store until August 13, as part of the 25th anniversary celebration of the Ghost Recon series. Additionally, there is a series-wide sale with discounts of up to 95% on previous Ghost Recon titles, including Ghost Recon Wildlands and Ghost Recon Breakpoint, which are available for free play from today until August 10. Chris Watters, Ubisoft's senior editorial communications manager, emphasized the significance of these offers. Ghost Recon: Future Soldier was originally released in May 2012 and received a Metacritic score of 79.
AppWizard
August 4, 2026
Google will require mandatory identity verification for all developers creating applications for the Android platform, affecting those from countries under U.S. sanctions, such as Russia, Iran, Cuba, and North Korea, who will be excluded from the verification system and may not distribute their apps internationally. The new regulations apply to developers of apps for Android 7 and later versions.
AppWizard
July 31, 2026
Major mobile carriers in Russia, including MTS, MegaFon, Beeline, and T2, have agreed to zero-rate data usage for the domestic Max messenger, effective August 1. This initiative aims to promote the state-approved platform and discourage the use of foreign messaging apps. Subscribers will have free access to voice calls, messaging, file transfers, and other services within the Max app. Since its launch in spring 2025, Max has been integrated into state digital services and mandated to be pre-installed on all smartphones sold in Russia, resulting in nearly 70 million daily active users. This announcement follows EU sanctions against VK, the app's developer, due to allegations of its connections with the Russian FSB and surveillance capabilities, leading to the removal of VK and Max from Apple and Google app stores.
Search