RedStinger

Aliases: Bad Magic

First seen
2022-10-01 00:00:00
Primary motivation
espionage
Sophistication
advanced
Resource level
government
Actor type
nation-state
Profile updated
2026-07-07 12:05:56

Targeted industries: government-and-public-sector transportation-and-logistics

Targeted regions: country_code:ua country_code:ru

Context

In October 2022, Kaspersky identified an active infection of government, agriculture and transportation organizations located in the Donetsk, Lugansk, and Crimea regions. Although the initial vector of compromise is unclear, the details of the next stage imply the use of spear phishing or similar methods. The victims navigated to a URL pointing to a ZIP archive hosted on a malicious web server.

Reports & references

  • malwarebytes.com — Redstinger (report)
  • Kaspersky — 109087 (report)

External references