Unidentified 002 (Operation Kremlin)

Malware type
dropper, spyware
Profile updated
2026-07-07 14:41:41

Targeted industries: government-and-public-sector

Targeted regions: country_code:ru

Context

Unnamed malware. Delivered as remote template that drops a VBS file, which uses LOLBINs to crawl the disk and exfiltrate data zipped up via winrar.

Reports & references

  • malpedia.caad.fkie.fraunhofer.de — Vbs.Unidentified 002 (report)
  • clearskysec.com — Operation Kremlin (report)

External references