---
title: "Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware"
url: https://daily.dev/posts/multi-stage-phishing-campaign-targets-russia-with-amnesia-rat-and-ransomware-wyyg7vpn0
source_url: https://thehackernews.com/2026/01/multi-stage-phishing-campaign-targets.html
type: article
source: "The Hacker News"
published: 2026-01-24T11:29:36.708Z
updated: 2026-01-24T11:29:56.694Z
tags: ["cyber", "windows", "malware", "ransomware", "phishing"]
reading_time: 6
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-Stage Phishing Campaign Targets Russia with Amnesia RAT and Ransomware

**[The Hacker News](https://daily.dev/sources/thn)** · 6 min read · 1 upvotes · 0 comments

## Summary

A sophisticated multi-stage phishing campaign targeting Russian organizations uses GitHub and Dropbox to distribute malware while disabling Microsoft Defender through the defendnot tool. The attack chain deploys Amnesia RAT for comprehensive data theft and remote control, along with Hakuna Matata-derived ransomware for file encryption. The campaign leverages social engineering with business-themed documents, PowerShell scripts, and Visual Basic scripts to establish persistence, disable security controls, and exfiltrate data via Telegram Bot API. Similar campaigns like Operation DupeHike are also targeting Russian corporate entities with DUPERUNNER implant and AdaptixC2 framework.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://thehackernews.com/2026/01/multi-stage-phishing-campaign-targets.html>

## Similar posts on daily.dev

- [Operation HumanitarianBait: An Infostealer Campaign](https://daily.dev/posts/operation-humanitarianbait-an-infostealer-campaign-mxpu5wjgr) · Cyble · 0 upvotes · 0 comments
- [Analyzing a a Multi-Stage AsyncRAT Campaign via Managed Detection and Response](https://daily.dev/posts/analyzing-a-a-multi-stage-asyncrat-campaign-via-managed-detection-and-response-dtjndshk8) · Trend Micro · 0 upvotes · 0 comments
- [From Phishing to Malware: AI Becomes Russia's New Cyber Weapon in War on Ukraine](https://daily.dev/posts/from-phishing-to-malware-ai-becomes-russia-s-new-cyber-weapon-in-war-on-ukraine-jdqsub135) · The Hacker News · 0 upvotes · 0 comments
- [New Malware Campaign Delivers Remcos RAT Through Multi-Stage Windows Attack](https://daily.dev/posts/new-malware-campaign-delivers-remcos-rat-through-multi-stage-windows-attack-c7pnftjdg) · The Hacker News · 0 upvotes · 0 comments
- [Inside SHADOW-WATER-063’s Banana RAT: From Build Server to Banking Fraud](https://daily.dev/posts/inside-shadow-water-063-s-banana-rat-from-build-server-to-banking-fraud-3oia9rsft) · Trend Micro · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#windows](https://daily.dev/tags/windows), [#malware](https://daily.dev/tags/malware), [#ransomware](https://daily.dev/tags/ransomware), [#phishing](https://daily.dev/tags/phishing)

[View this post on daily.dev](https://daily.dev/posts/multi-stage-phishing-campaign-targets-russia-with-amnesia-rat-and-ransomware-wyyg7vpn0)
