Remove 2024 Remove Encryption Remove Workplace Security
article thumbnail

Batavia spyware steals data from Russian organizations

SecureList

The campaign began in July 2024 and is still ongoing at the time of publication. vbe , encrypted using Microsoft’s proprietary algorithm (MD5: 2963FB4980127ADB7E045A0F743EAD05). In response, javav.exe receives a new C2 address, encrypted with a 232-byte XOR key, which is saved to a file named settrn.txt.

Spyware 79