Malware Campaign Impersonates European Donors to Target Moldovan Media and Civil Society

Between September 9 and 25, 2026, an attacker targeted Moldovan media and civil society with fraudulent event invitations and grant offers with malware impersonating three European organizations: European Business Summits, a Brussels-based organizer of conferences for business and policy leaders; the European Endowment for Democracy, a Brussels-based foundation supporting pro-democracy activists and independent media; and East Europe Foundation Moldova, a Chișinău-based foundation supporting civil society.

RESIDENT.NGO analyzed the attack and documented five recipients of the campaign: three media outlets, a media support organization, and a civil society organization.

The initial email sent to each recipient contained no malicious attachment. Recipients who replied and expressed interest were then sent a password-protected archive containing a Windows virtual disk image (a VHDX file). Inside the disk image was a shortcut disguised and styled as a document. When opened, it displayed a decoy PDF while silently launching a hidden loader that communicated with attacker-controlled servers and accepted commands from them. The command we observed created recurring scheduled tasks on the computer, providing a mechanism for delivering additional malware.

The techniques used in this campaign closely resemble those that Microsoft has linked to the Russian state-linked group Star Blizzard. However, the evidence available to RESIDENT.NGO is insufficient to attribute this campaign to that group.

Part I — The story

1. A fake invitation

On September 9, 2026, a senior staff member of a Moldovan media support organization received an invitation to a “European Democracy Summit” in Brussels from someone posing as the Director General of European Business Summits. The event and the executive’s name are real; the sender was not. The email said a personal invitation was attached, but the only attachment was the organizer’s logo.

Figure 1: The September 9 email promising a personal invitation. The recipient’s name and address are redacted.

On the same day, someone in Chișinău, Moldova’s capital, uploaded to VirusTotal a malicious disk image named after the same event. VirusTotal is a public service used to analyze suspicious files. The upload suggests a copy of the same malicious file was circulating in Moldova at the time of the campaign. We do not know who uploaded it or why, and we are not aware whether the uploader was one of the five targets we identified.

2. Grant offers to a newsroom

Then, on September 17, 2026, a Moldovan newsroom received an offer of media cooperation purportedly from the European Endowment for Democracy. A week later, on September 24, a second sender approached the same newsroom with a grant offer while posing as East Europe Foundation Moldova. Neither email address belonged to the organization it claimed to represent. The first mailbox was on the website of a cleaning company in Greece, the second on another website unrelated to the foundation; the foundations’ names appeared only in the senders’ display names.

The newsroom replied to the grant offer and asked for the proposal document. The attacker then sent them a password-protected ZIP archive containing a Windows virtual disk. A virtual disk (a .vhdx file) is an image of a drive: when opened, Windows attaches it as a separate drive and shows its files as if they were on a local disk. The only visible file on the disk was a shortcut named like the proposal, EEF_Moldova_Participation_Proposal_DRAFT, with a generic document icon. Windows hides the shortcut’s .lnk extension, so it looks like an ordinary document.

Figure 2a: Opening the archive in Windows File Explorer. Inside is a single virtual disk file, and Windows asks for the password given in the email. The archive shown was sent to the second outlet on September 25; the one sent to the newsroom on September 24 looks the same.

Figure 2b: The opened virtual disk with Windows’ default settings, as the recipient would see it: a single shortcut named like a document.

Figure 2c: The same disk with hidden items shown. The hidden folder documentvault holds the decoy PDF and the malware that the shortcut starts; $RECYCLE.BIN and System Volume Information are standard system folders.

The newsroom reported that the disk would not open and asked for a PDF or Word file. The sender claimed to always send protected documents this way and asked whether the newsroom’s system would allow the file once the source was confirmed.

These later replies appear to have been written by a person rather than sent automatically. Each came within about an hour of the newsroom’s message (51 and 77 minutes), responded to what the newsroom had just written, and the last one addressed the staff member by the first name from their signature.

Figure 3: The attacker’s reply containing the password-protected archive, with the password provided in the email body. The newsroom’s earlier request for the proposal is quoted below. The newsroom’s name has been redacted.

The same September 24 mailing also reached two additional media outlets and a civil society organization. One of the outlets replied and, on September 25, received a password-protected archive containing a revised version of the malware sent to the first newsroom the previous day. The initial emails were not sent manually from a conventional email client or webmail interface. Instead, they were distributed by a script working through a list of recipient addresses, suggesting that the campaign likely reached more than the five recipients we were able to document.

3. How the attack works

The goal of this attack was to install malware on a Windows computer:

  1. Conversation first. The initial email asks only whether the organization is interested. The file arrives after the recipient has replied, so it looks expected.
  2. A disguised file. The password-protected archive contains a virtual disk, with the password provided in the email text. Inside the disk image is a shortcut named and styled like a document. Files opened from a mounted disk image may not retain the ‘Mark of the Web’ Windows adds to files downloaded from the internet, so Windows may show no security warning when the shortcut is opened.
  3. A decoy and a hidden program. Opening the shortcut shows a convincing PDF proposal and, at the same time, starts a hidden program.
  4. A call to the attacker’s server. The hidden program contacts the attacker’s server and runs the instructions it receives.
  5. Regular check-ins with the attacker. Those instructions create recurring Windows tasks that contact attacker-controlled servers every 12 to 15 minutes and report the computer and user name. Through these tasks, the attackers can deliver additional malware at any time and choose which victims receive further payloads.

Figure 4: The decoy PDF that the shortcut opens while the loader starts in the background: the grant “invitation to participate” in the name of East Europe Foundation Moldova, used in the September 24 and 25 builds.

We did not obtain this additional malware, and have not confirmed any infection of recipients’ devices.

4. Similarity to Star Blizzard’s RedFlick

On September 29, 2026, Microsoft reported on a technique it calls RedFlick, used in 2026 by the Russian state-linked group Star Blizzard against non-governmental organizations, think tanks, and others supporting Ukraine.

The campaign we observed shares several of RedFlick’s key characteristics: invitations from real organizations, a conversation before any file is sent, one mailbox name reused across several unrelated websites (in this campaign, TatianaSimonov), payload delivery through a virtual disk and recurring tasks, and the same hosting company for some of the attacker’s servers.

The disk images in this case, however, carry different traces of the computer used to build them, namely a different Windows account and a differently formatted computer name inside the shortcuts (Section 7). Researchers usually link a campaign to a known group through shared server addresses and file fingerprints, and none of those Microsoft published appear here. We therefore cannot conclusively attribute this campaign to Star Blizzard, even though the techniques are very similar.

Even earlier, in June 2026, Digital Security Lab Ukraine described a similar campaign against Ukrainian civil society organizations: fake invitations to the Ukraine Recovery Conference, a password-protected archive with a virtual disk, and scheduled tasks that contact attacker servers. Microsoft later listed some of that campaign’s indicators as part of RedFlick.

5. Advice for organizations

Grant offers and event invitations do not come as virtual disks or as password-protected archives containing shortcuts. Attackers password-protect archives because the password keeps the automatic scanners of large email providers from looking inside, so a password in the email text is itself a warning sign. Treat such a file as an attack and do not open it, even if the sender and the offer look genuine. Confirm unexpected offers with the organization through a contact you already know. If a malicious file was opened on Windows, disconnect the computer from the network immediately and contact cybersecurity or IT specialists; the indicators they need are in Part II and Appendix B.

Email administrators can block attachments with .vhd, .vhdx, .iso, .img, and .lnk files, including inside archives, and consider holding password-protected archives for manual review.

If your organization received similar emails, or you want to check whether a device was infected, contact RESIDENT.NGO at [email protected].

Part II — Technical analysis

6. Evidence and methods

We analyzed the original emails, three versions (builds) of the malicious disk image, the files extracted from them, a C2 (command and control server) response that we captured on September 29 and 30, 2026, VirusTotal sandbox reports on the September 9 and September 24 builds, and VirusTotal and Censys records.

7. Three builds, one operation

DateLureWhat is special about this build
September 9, 2026European Democracy Summit invitationLoader siemens.exe in a hidden folder documents; decoy PDF made with ReportLab, carrying a ChatGPT C2PA manifest
September 24, 2026Grant proposal to the first newsroomLoader leaf.exe with an internet connectivity check against google.com; hidden folder renamed documentvault; decoy generated as a Word file by a Python script (python-docx) and converted to PDF with LibreOffice, about two hours before the loader was compiled
September 25, 2026Grant proposal to the second newsroomLoader split into cleaner.exe and libssl52.dll; command address XOR-encrypted with a key passed by the batch file

What stays the same across all three builds matters more than what changes:

  • the same infection chain (Section 8);
  • the same builder fingerprint in the three disk images (VHDX files): the SID of a built-in Administrator account, S-1-5-21-4080033715-524121986-3969075855-500, in the recycle-bin metadata, and shortcuts whose MachineID holds a 16-character upper-case DESKTOP-… name, longer than the 15-character NetBIOS name this field normally holds. This shows the images were built on the same Windows installation or copies of it;
  • the same follow-up: a PowerShell command that registers WebDAV scheduled tasks (Section 9);
  • the same sending server for the first emails (Section 10);
  • a reused third-party WebDAV server (Section 9).

The September 9 and 24 loaders also send a byte-identical User-Agent, the identifier a program includes with every web request, and the two grant builds share the same decoy PDF. Together, these tie the three builds and all the emails to one operation.

Each wave was prepared shortly before sending: the September 24 command domain was registered about four hours before the first email to the newsroom and the loader compiled about 17 hours before the grant mailing; when that server stopped responding, the operator registered a replacement within 12 hours and sent a rebuilt image the same afternoon.

Comparison with RedFlick. Beyond the parallels listed in Section 4, the campaign’s command and WebDAV domains were registered in pairs at Openprovider within minutes of each other, as was the most recent RedFlick pair Microsoft published, and one RedFlick domain used the same /24 address block at RoyaleHosting as this campaign’s command servers, in February 2026. The differences are in the builds: the RedFlick images published by Microsoft contain ordinary user SIDs and lowercase, null-terminated MachineIDs, while this campaign uses one administrator SID and uppercase, unterminated MachineIDs. Attribution to Star Blizzard remains a low-confidence hypothesis.

8. Infection chain

Email → password-protected ZIP → VHDX → document-named LNK → batch file (.bat) → decoy PDF + loader → HTTPS command request

The password-protected ZIP is known only for the September 24 and 25 builds; how the September 9 image was delivered is not known. The shortcut, whose description field holds the document name ending in .pdf, runs conhost.exe –headless, which starts a batch file in a hidden folder. The batch file opens the decoy and launches the loader. The loader is a small 64-bit Windows program written in C/C++ and compiled with Microsoft Visual C++. Its only job is to request one command from a built-in server address over HTTPS, ignoring certificate errors, and to run the reply as a hidden process. In all four loader files (siemens.exe, leaf.exe, cleaner.exe and libssl52.dll), the Rich header, a block the Microsoft compiler adds to record the tools and versions used in the build, has been removed. Researchers use this header to link samples built in the same environment, so removing it makes the files harder to connect to other malware from the same developer. The September 24 and 25 versions first check that the computer is online by contacting google.com and facebook.com respectively. In the September 25 build, the loader needs an argument from the batch file to decrypt its server address, so the executable run on its own shows no network activity; analysts should run the full chain rather than the loader alone.

Figure 5: Contents of the hidden documentvault folder on the September 24 disk, which Windows mounts as drive “Documents (G:)”: the batch file, the decoy PDF and the loader leaf.exe. The batch file, opened in Notepad, holds two commands: open the decoy and start the loader.

9. Command servers and persistence

In every command-server reply we have, captured by VirusTotal sandboxes for the September 9 and 24 builds and by our own requests to the September 25 command server, the reply is a PowerShell script that registers scheduled tasks of two kinds:

  • a task that runs control.exe, the standard Windows program for opening Control Panel items, on an attacker’s WebDAV server path every 12 or 15 minutes, with a Base64 DOMAIN\COMPUTER\USER label in the path;
  • a supporting task that runs explorer.exe on a third-party WebDAV server at logon (hourly in the September 9 build), so that WebDAV access works on the computer.

According to DSLUA and Microsoft, which described the same technique, the first kind of task makes Windows load a Control Panel applet (a DLL) from the attacker’s server, and the second starts the Windows WebClient service the first one needs.

The September 24 build adds a second control.exe task pointing to the WebDAV server’s IP address, 91[.]190[.]100[.]194. The supporting task points to third-party servers that appear to be compromised: www[.]scfbio-iitd[.]res[.]in:8080 in the September 9 and 25 builds and 200[.]19[.]215[.]32:8080 in the September 24 build. The September 25 command server still served the same command on September 30. The WebDAV server rakuda[.]top refused our requests (HTTP 403), so the payload behind the WebDAV path was not obtained.

10. Email infrastructure

In all five sets of original headers, the first-contact emails entered the mail system from the same server, 77[.]73[.]39[.]2 (Host4Biz, Poland). The attacker’s follow-up replies were written in the webmail of the sender mailboxes, not sent by the script. The first emails were sent by a Python script: their Message-IDs end in @lenovo-pc, and their Roundcube Webmail User-Agent is forged. The mailbox name TatianaSimonov was created on four unrelated websites, and one of them, smartidea[.]co[.]nz, also hosted the sender of the September 9 invitation. The sending server was still online on September 30, 2026, and its SSH host key had not changed since at least July 31, 2026, the start of the scan history available to us, which indicates the operator has kept the same server throughout the campaign.

11. Detection

Look for ZIP archives containing VHDX images, shortcuts that launch conhost.exe –headless, scheduled tasks running control.exe with a DavWWWRoot path, and first-contact emails with a Roundcube Webmail User-Agent but Python-style Message-IDs. Indicators are listed in Appendix B, and ATT&CK techniques in Appendix C.

Appendices

A. Build comparison

BuildLoaderCommand domainWebDAV domain
September 9, 2026siemens.exeamoram[.]tophasxb[.]top
September 24, 2026leaf.exeonjata[.]toptunzex[.]top
September 25, 2026cleaner.exe + libssl52.dllpeysafe[.]toprakuda[.]top

B. Indicators for defenders

Files (SHA-256).

BuildFileSHA-256
September 9, 2026VHDX6cb184adfe6f1438a7a0e057ef12946b16c69fb442cedda9b80ce8e81f3f6080
September 9, 2026LNK80bc815a97d31196fafb1e324b321e0c6b998f133590b06d7f2bccd5b9761e3d
September 9, 2026BAT8abbbdc1664b89613721ce96f867bd6c05da99368e8ed017ec0e88cbeabe3f5c
September 9, 2026Decoy PDF491684aa36ee73153621d1715001978741bc0c457bb07ad5fe70b38ebd29215a
September 9, 2026siemens.exedee49a09c1f767e0ad41d354898315c24680b88b31b7eed723dc484bed6b053b
September 24, 2026ZIPe3a64a72fcd8808b49c147b2ddcabc58286ad537ba3e83416bc9b46c587bcd37
September 24, 2026VHDXdf0372bc4740540473f18e677c195fbc121a6bc1a9de0be2258ab936f2d161c7
September 24, 2026LNK18ac4c74e145bd6c07c82fde19d9978ee033ad2165bea46e1518566920ba0abf
September 24, 2026BATbdc798b27edc8fad63f12191092ee4167f0552829058dcb2a7203d7b7903325f
September 24/25, 2026Decoy PDF21e91863a61b7c3b872fccb57d8eaff5befab987de50276c6cbcc5323fc43362
September 24, 2026leaf.exe5e88fb2da3af531c506a745f6ef005fde861a3ad0f95c28939ab843bd1e6916a
September 25, 2026ZIP7d2409f066a35800d5c135f5c281f8b15fb09de16d743f5b6aca43857ff0c0cb
September 25, 2026VHDX3a5293b6d0b1d321772d642fee629e03bff8e4232b50a1e10410f2360dc0aa16
September 25, 2026LNK44142612cf4954644804327c8876a8178d3bbf3d13ac7c5704f2373281fa5cb4
September 25, 2026BAT5c6b30bda62955e8b6d0ad0c7a53e50b511a4ce2d13637af57048d39c358ecdd
September 25, 2026cleaner.exe9ca6cef63742b4f39a67d3b0f6f34ed5e5f88c3183452017286a0b4c2a0df639
September 25, 2026libssl52.dll27519ad6dea113965e22b037f3d4cc80cc1da9cc48294b2cce143fa08316acfa

Network. Addresses were used by the campaign on the dates shown; 45[.]140[.]213[.]2 has since been reassigned; 77[.]73[.]39[.]2 was still online on September 30, 2026.

RoleIP address
Email sending server, Host4Biz77[.]73[.]39[.]2
Campaign command/WebDAV, RoyaleHosting45[.]140[.]213[.]2 (September 18, 2026, 11:36 – September 24, 2026, 21:09 UTC), 45[.]140[.]213[.]185, 45[.]140[.]213[.]188, 91[.]190[.]100[.]194
Campaign command/WebDAV, later build104[.]194[.]141[.]111, 144[.]172[.]119[.]186
Third-party WebDAV; possible compromised services111[.]91[.]225[.]18, 200[.]19[.]215[.]32

Sender mailboxes (on websites unrelated to the impersonated organizations): ArnaudThysen[at]smartidea[.]co[.]nz, Alexandra.Kirby[at]uniquefam[.]gr, and TatianaSimonov[at] each of accessharbour[.]com, smartidea[.]co[.]nz, amrep-ec[.]com, and angkol[.]co[.]tz.

Scheduled tasks. Search task names and their control.exe or explorer.exe actions: September 9 CB-FB-AF-12-AA, a34fcc20-47df-3f0e-a78e-02c128c6f9ec; September 24 4f46a6e7-afd9-45cb-990c-3184afc48eb9, 83f5b6f7-ca22-4463-a9ae-26b910426282, aeae76b9-6d4e-412a-a892-545488a19de6; September 25 7d6adf3a-991d-4002-bf56-786bc617efa7, c00ee668-f011-49d0-b044-31ece95586bd.

Other. ZIP password: mintClownVenus$. The September 9 and 24 loader User-Agent is Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 10.0; Win64; Chrome/151.0.0.1 x64; Trident/7.0; .NET4.0C WindowsPowerShell); the September 25 build changes Chrome/151.0.0.1 to Chrome/162.0.0.1.

C. MITRE ATT&CK techniques

Techniques follow MITRE ATT&CK Enterprise v19. Techniques marked likely rest on circumstantial evidence.

  • Resource Development: command and WebDAV domains registered in pairs (T1583.001) and pointed at rented servers (T1583.003); sender mailboxes created on unrelated third-party websites, likely compromised (T1586.002); third-party WebDAV servers used in the supporting task, likely compromised (T1584.004); decoy documents generated for each wave (T1683.001).
  • Initial Access and Execution: first contact without an attachment, then a password-protected ZIP after the recipient replies (T1566.001), in the name of real organizations (T1684.001); the recipient opens a shortcut (T1204.002), which runs a batch file (T1059.003); the loader runs a PowerShell command received from the server (T1059.001).
  • Stealth and Defense Impairment: a virtual disk that can let files bypass Mark-of-the-Web (T1553.005); a shortcut disguised as a document (T1036) and loader files named like legitimate software (T1036.005); payload in a hidden folder (T1564.001); launch through conhost.exe –headless (T1202); a remote applet loaded through control.exe (T1218.002); the command server address XOR-encrypted in the September 25 build (T1027.013).
  • Persistence and Discovery: scheduled tasks that contact the attacker every 12 to 15 minutes (T1053.005); an internet connectivity check before contacting the server (T1016.001); computer and user name sent in the WebDAV path (T1033).
  • Command and Control: command requests over HTTPS (T1071.001); scheduled tasks that let the attacker deliver further programs over WebDAV (T1105).