Cybercriminals target accountants to drain Russian firms’ bank accounts
嗯,用户让我总结一下这篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读这篇文章,理解其主要信息。 文章讲的是网络犯罪分子通过入侵会计师的电脑,伪装成工资支付,从俄罗斯公司盗取了数百万资金。具体来说,他们使用钓鱼邮件传播恶意软件DarkWatchman,进而控制公司支付系统。攻击者伪装成合法的薪资转账,将资金转移到自己控制的账户中。超过3000家俄罗斯组织受到了影响,最大的盗窃金额超过1400万卢布。 接下来,我需要将这些信息浓缩到100字以内。重点包括:网络犯罪、入侵会计师电脑、伪装薪资转账、钓鱼邮件、恶意软件DarkWatchman、资金转移、影响范围和金额。 可能的结构是:网络犯罪分子通过钓鱼邮件和恶意软件入侵会计师电脑,伪装薪资转账从俄罗斯公司盗取资金。超过3000家组织受影响,最大损失超1400万卢布。 这样既涵盖了主要事件、手段和影响范围,又符合字数限制。 </think> 网络犯罪分子通过入侵会计师电脑并伪装薪资转账从俄罗斯公司盗取资金。攻击者利用钓鱼邮件传播恶意软件DarkWatchman控制企业支付系统。超3,000家俄组织受影响,最大损失超1,400万卢布。 2026-4-9 10:31:7 Author: therecord.media(查看原文) 阅读量:8 收藏

Cybercriminals have stolen millions from Russian companies by hacking accountants’ computers and disguising transfers as salary payments, according to areport released this week.

Researchers at Russian cybersecurity firm F6 said the financially motivated groupHive0117 carried out a wave of attacks from February to March 2026 targeting corporate finance departments.

The attackers used phishing emails to infect accountants’ computers with malware, allowing them to access remote banking systems used to manage company payments.

Once inside, the hackers created payment orders that appeared to be legitimate salary transfers but in fact routed funds to accounts they controlled.

More than 3,000 Russian organizations received the malicious emails, researchers said. The largest confirmed theft exceeded 14 million rubles (about $178,000).

According to the report, the attackers carefully tailored their phishing emails to employees working in accounting or finance departments.

The emails were sent from what appeared to be legitimate but likely compromised accounts, including one belonging to a Moscow-based web and mobile application developer. Attached files were packaged in password-protected archives disguised as routine business documents such as invoices, reconciliation statements and shipping paperwork.

When victims opened the archive and executed a hidden file inside, their computers became infected with DarkWatchman, a remote access trojan that allows attackers to maintain covert control over compromised systems.

DarkWatchman gives attackers the ability to run commands remotely, download additional malicious tools and move laterally across a company’s network, researchers said. The malware has been linked to Hive0117 since at least 2021 and is typically distributed through phishing campaigns.

With control of an accountant’s machine, attackers could log into corporate online banking portals and initiate transactions directly from the compromised system, making the activity appear legitimate.

In the recent campaign, the hackers exploited payroll mechanisms by creating payment orders tied to bank accounts stored in a registry that appeared to belong to employees but were actually controlled by the attackers.

If those transfers cleared bank anti-fraud controls, the criminals were able to withdraw large sums from company accounts, the report said.

Hive0117 has been active since late 2021 and primarily targets financial departments across multiple industries. While most recent attacks focused on Russian organizations, previous activity has also targeted users in Lithuania, Estonia, Belarus and Kazakhstan, according to F6.

Researchers previously said the group’s operations do not appear to be connected to the broader cyber conflict between Russia and Ukraine, and the attackers’ origin remains unknown.

The latest campaign follows earlier activity reported by F6 last year, when the group used a modified version of DarkWatchman to target Russian companies across multiple sectors.

In 2023, Western researchers also observed Hive0117 impersonating Russian government communications in phishing emails disguised as military conscription notices, another campaign that deployed the same malware.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.


文章来源: https://therecord.media/cybercriminals-hack-russian-accountants-to-steal-millions
如有侵权请联系:admin#unsafe.sh