Cyber News

Malicious Word Document Delivers Spyware to Batavia Employees – A Stealthy Malware Attack

A sophisticated cyberattack campaign, first detected in July 2024 and continuing into 2025, has put Russian industrial enterprises on high alert.

Security researchers have identified a series of phishing emails carrying malicious attachments disguised as official documents, primarily Word files named in Russian, such as договор-2025-5.vbe (“contract”) and приложение.vbe (“attachment”).

When an unsuspecting employee clicks these lures, a stealthy multi-stage malware, now dubbed “Batavia spyware,” is unleashed to harvest sensitive documents and internal data.

Technical Details – Three-Stage Infection Chain

The Batavia attack relies on a well-crafted and persistent social engineering strategy. Victims receive emails from addresses associated with the malicious domain oblast-ru[.]com, urging them to review or sign an urgent contract.

The “document” is, in fact, a link to a maliciously crafted VBS script archive.

Stage One: VBS Downloader Script
Upon execution, the VBS script connects to the attackers’ server, retrieves system information, and downloads an executable named WebView.exe (MD5: 5CFA142D1B912F31C9F761DDEFB3C288).

This downloader also determines the OS version, selects the correct infection route, and creates a decoy file to mask its activities.

Example of an email with a malicious link

Stage Two: WebView.exe Spy Module
WebView.exe, written in Delphi, masquerades as a legitimate application window while silently exfiltrating files and system logs and periodically capturing screenshots. It transmits the stolen data to another attacker-controlled domain, ru-exchange[.]com.

To ensure persistence, WebView.exe schedules the execution of a follow-up module, java.exe, after the next system reboot.

Stage Three: Advanced Data Theft and C2 Communication
Javav.exe (MD5: 03B728A6F6AAB25A65F189857580E0BD), built in C++, expands its file-stealing reach to include office documents, spreadsheets, emails, images, and archives.

It can also receive and execute further malicious payloads via encrypted instructions from the attacker’s C2 infrastructure, employing techniques to bypass standard user account control (UAC) protections.

Widespread Impact and Recommendations

Kaspersky telemetry indicates that the campaign has targeted over 100 devices across dozens of Russian organizations. The attackers’ infrastructure employs constantly changing identifiers to track each infection, enhancing its stealth and evasion capabilities.

To defend against such threats, experts recommend implementing comprehensive endpoint security, conducting regular threat hunting, and providing ongoing employee cybersecurity training.

Organizations should prioritize phishing awareness, as malicious emails disguised as official business communications remain the primary infection vector.

Indicators of compromise include:

  • Malicious file hashes:
    • Договор-2025-2.vbe: 2963FB4980127ADB7E045A0F743EAD05
    • WebView.exe: 5CFA142D1B912F31C9F761DDEFB3C288
    • Javav.exe: 03B728A6F6AAB25A65F189857580E0BD
  • Command and control domains: oblast-ru[.]com, ru-exchange[.]com

Security teams are urged to remain vigilant as the Batavia spyware continues to evolve and adapt its methods to evade detection.

Priya

Recent Posts

Burp Suite Supercharges Its Scanning Capabilities With React2Shell Vulnerability Detection

PortSwigger has leveled up Burp Suite's scanning arsenal with the latest Active Scan++ extension, version…

5 months ago

Malicious MCP Servers Enable New Prompt Injection Attack To Drain Resources

Unit 42 researchers at Palo Alto Networks exposed serious flaws in the Model Context Protocol…

5 months ago

Law Enforcement Detains Hackers Equipped With Specialized Flipper Hacking Tools

Polish police have arrested three Ukrainian men traveling through Europe and seized a cache of…

5 months ago

Google Unveils 10 New Gemini-Powered AI Features For Chrome

Google has launched its most significant Chrome update ever, embedding Gemini AI across the browser…

5 months ago

CISA Alerts On Actively Exploited Buffer Overflow Flaw In D-Link Routers

Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by…

5 months ago

Over 500 Apache Tika Toolkit Instances Exposed To Critical XXE Vulnerability

Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for…

5 months ago