Перейти к содержанию

Hacker Group Attacks Russian Organizations with Penetration Testing Tool

By its capabilities, Ravage is similar to remote access tools.

Cybersecurity experts from Kaspersky Lab have identified a new cyber group targeting Russian organizations, including educational institutions and energy companies. A key feature of the attacks is the use of the Ravage framework – a tool originally intended for penetration testing, but used by attackers for remote system management.

The attacks, which began in January 2026, use phishing emails with malicious archives. Inside are files disguised as Excel documents. When opened, a downloader is launched, which downloads and activates malware components, ultimately loading Ravage via a PowerShell script.

Cybersecurity expert Oleg Kupreev explained:

By its capabilities, Ravage is similar to Remote Access Tools. The framework can perform file manipulations – upload, download, copy, and delete, launch processes, and execute PowerShell scripts received from the attackers' server. Ravage can also take screenshots and execute commands on local network computers via SMB or WMI. All of this relates to basic functionality, but it cannot obtain tickets, tokens, saved passwords, or create hidden control channels within the infected network.

Over the past year, half of the recorded attacks targeted Russian educational institutions, mainly those related to water transport. Organizations in the energy, government, and financial sectors were also affected. According to the study, the group has been active since at least 2024 and operates systematically, indicating that its members have experience.