Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society
Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society 🚨
Between September 9 and 25, 2026, an attacker targeted Moldovan media and civil society with fraudulent event invitations and grant offers containing malware impersonating three European organizations: European Business Summits, European Endowment for Democracy, and East Europe Foundation Moldova. RESIDENT.NGO analyzed the attack and documented five recipients of the campaign, including three media outlets and a civil society organization.
The initial email sent to each recipient contained no malicious attachment. Recipients who replied and expressed interest were then sent a password-protected archive containing a Windows virtual disk image (a VHDX file). Inside the disk image was a shortcut disguised as a document. When opened, it displayed a decoy PDF while silently launching a hidden loader that communicated with attacker-controlled servers.
The techniques used in this campaign closely resemble those linked to the Russian state-linked group Star Blizzard. However, the evidence available to RESIDENT.NGO is insufficient to attribute this campaign to that group.
On September 9, 2026, a senior staff member of a Moldovan media support organization received an invitation to a “European Democracy Summit” from someone posing as the Director General of European Business Summits. On the same day, a malicious disk image named after the same event was uploaded to VirusTotal. On September 17, a Moldovan newsroom received an offer of media cooperation purportedly from the European Endowment for Democracy. A week later, on September 24, a second sender approached the same newsroom with a grant offer while posing as East Europe Foundation Moldova.
The attacker sent a password-protected ZIP archive containing a Windows virtual disk. The only visible file on the disk was a shortcut named like the proposal, EEF_Moldova_Participation_Proposal_DRAFT, with a generic document icon. Windows hides the shortcut’s .lnk extension, making it look like an ordinary document. These later replies appeared to have been written by a person rather than sent automatically.
The goal of this attack was to install malware on a Windows computer. The process involved a conversation first, where the file arrives after the recipient has replied, making it look expected. This was followed by a disguised file, which was a password-protected archive containing a virtual disk with a shortcut named and styled like a document. Opening the shortcut triggers a decoy and a hidden program, showing a convincing PDF proposal while starting a hidden program that contacts the attacker’s server.
For more details, check out the full article: Read full article