Post

Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society

Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society

Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society 🚨

Between September 9 and 25, 2026, an attacker targeted Moldovan media and civil society with fraudulent event invitations and grant offers containing malware impersonating three European organizations: European Business Summits, European Endowment for Democracy, and East Europe Foundation Moldova. RESIDENT.NGO analyzed the attack and documented five recipients of the campaign, including three media outlets and a civil society organization.

The initial email sent to each recipient contained no malicious attachment. Recipients who replied and expressed interest were then sent a password-protected archive containing a Windows virtual disk image (a VHDX file). Inside the disk image was a shortcut disguised as a document. When opened, it displayed a decoy PDF while silently launching a hidden loader that communicated with attacker-controlled servers.

The techniques used in this campaign closely resemble those linked to the Russian state-linked group Star Blizzard. However, the evidence available to RESIDENT.NGO is insufficient to attribute this campaign to that group.

On September 9, 2026, a senior staff member of a Moldovan media support organization received an invitation to a “European Democracy Summit” from someone posing as the Director General of European Business Summits. On the same day, a malicious disk image named after the same event was uploaded to VirusTotal. On September 17, a Moldovan newsroom received an offer of media cooperation purportedly from the European Endowment for Democracy. A week later, on September 24, a second sender approached the same newsroom with a grant offer while posing as East Europe Foundation Moldova.

The attacker sent a password-protected ZIP archive containing a Windows virtual disk. The only visible file on the disk was a shortcut named like the proposal, EEF_Moldova_Participation_Proposal_DRAFT, with a generic document icon. Windows hides the shortcut’s .lnk extension, making it look like an ordinary document. These later replies appeared to have been written by a person rather than sent automatically.

The goal of this attack was to install malware on a Windows computer. The process involved a conversation first, where the file arrives after the recipient has replied, making it look expected. This was followed by a disguised file, which was a password-protected archive containing a virtual disk with a shortcut named and styled like a document. Opening the shortcut triggers a decoy and a hidden program, showing a convincing PDF proposal while starting a hidden program that contacts the attacker’s server.

For more details, check out the full article: Read full article

This post is licensed under CC BY 4.0 by the author.