Google Links Suspected Russian-Linked Actor to CANFAIL Attacks on Ukrainian Organizations
Google’s Threat Intelligence Group (GTIG) has connected a newly observed threat actor to a series of intrusions that delivered a malware family known as CANFAIL against targets in Ukraine. GTIG believes the group may have ties to Russian intelligence services and notes the actor has focused its efforts on entities within Ukraine’s defense, military, government and energy sectors.
Beyond those primary targets, GTIG reports the actor has broadened its attention to include aerospace companies, manufacturers with military or drone-related operations, research institutions working on nuclear and chemical topics, and international organizations involved in monitoring the conflict or providing humanitarian aid in Ukraine.
Although GTIG characterizes this actor as having fewer resources and less technical sophistication than many other Russia-linked threat clusters, the group has recently begun leveraging large language models (LLMs) to mitigate some of its operational shortcomings. According to Google, the actor uses LLMs to assist with reconnaissance, craft social-engineering lures, and answer basic technical questions related to post-compromise tasks and command-and-control infrastructure setup.
Recent phishing operations attributed to the group involved impersonations of legitimate Ukrainian national and regional energy providers to trick victims into revealing organization and personal email credentials. The actor has also posed as a Romanian energy supplier that serves Ukrainian clients, targeted a Romanian company, and performed reconnaissance against organizations in Moldova.
To prepare campaigns, the group compiles tailored email lists based on industry and geographic research. Attack chains observed by GTIG include LLM-generated bait and links hosted on Google Drive that point to a RAR archive containing the CANFAIL payload. The malware is commonly disguised using a double file extension (for example, a filename ending in .pdf.js) to appear like a PDF while actually being an obfuscated JavaScript program.
When executed, the CANFAIL JavaScript runs a PowerShell script which then downloads and launches a memory-resident PowerShell dropper, avoiding writing the secondary payload to disk. At the same time, the infection displays a bogus “error” dialog to the user to mask the activity.
GTIG also tied the same actor to a campaign called PhantomCaptcha, which SentinelOne’s SentinelLabs disclosed in October 2025. That operation used phishing messages to steer recipients to fraudulent pages that hosted ClickFix-style guidance purporting to instruct users how to complete the required steps to trigger the compromise. The PhantomCaptcha chain ultimately delivered a WebSocket-based trojan.
This activity underscores continuing threats to critical infrastructure and organizations involved with Ukraine, combining social engineering, relatively simple yet effective malware, and the increasing adoption of generative AI tools to scale reconnaissance and lure development.