Перейти к содержанию

Buhtrap Attacks Accountants Again via Decoy Websites

Users think they are downloading a document, but instead receive an archive with malware.

Specialists from the F6 Cybersecurity Center detected a new campaign to distribute Buhtrap RAT malware in September 2026. Attackers once again targeted employees of accounting and legal departments, using fake websites promoted through search engine advertising.

Image generated by Grok neural network

Another decoy mimics the resource "Glavnaya Kniga Bukhgaltera" (Chief Accountant's Book). A user who navigates to the page from search results sees a regular button for downloading a document. However, instead of the file, JavaScript code replaces the download and directs the victim to a ZIP archive containing malware.

The archive name is automatically generated from the download date and time. After launching Buhtrap RAT, the infection continues according to the scheme previously recorded by F6 specialists. No significant changes have been found in the malware itself or the attack sequence.

The attackers made the main adjustments to the network infrastructure. At the same time, specialists note that the scheme itself remains practically the same: a fake specialized resource, promotion through search, and replacement of the expected document with a malicious archive.