A previously undocumented spyware called ‘Batavia’ has been targeting large industrial enterprises in Russia in a phishing email campaign that uses contract-related lures. The researchers believe the operation has been active since at least last year in July and is ongoing. Based on telemetry data, the phishing emails delivering Batavia have reached employees at several dozen Russian organizations have been targeted. Since January 2025, the campaign has increased in intensity and peaked towards the end of February. Researchers at Kaspersky say that the attacks begin with an email embedding a link disguised as a contract attachment. Clicking it downloads an archive that with a malicious Visual Basic Encoded script (.VBE) file. When executed, the script profiles the host system and sends the details to the attacker’s command and control server (C2). Then it downloads the next stage payload, WebView.exe, from oblast-ru[.]com. The second stage is a Delphi-based malware that displays a fake contract to the victim for diversion while collecting system logs, documents, and capturing screenshots in the background. The collected data is then exfiltrated to ru-exchange[.]com, while the malware uses a hash of the first 40,000 bytes of each file to avoid redundant uploads. Finally, it fetches the third-stage payload, ‘javav.exe,’ a C++ data stealer, and adds a startup shortcut to execute it on OS boot. The final payload expands the data collection even more, targeting additional file ty...
'Batavia' Windows spyware campaign targets dozens of Russian orgs
BleepingComputer
·Bill Toulas
·Published Jul 7, 2025
·Updated
Affected Software
3 affected components
Kaspersky N/A
Visual Basic N/A
Delphi N/A
Frequently Asked Questions
1
What is the main subject of the article?
The article discusses a spyware campaign named 'Batavia' that targets large industrial enterprises in Russia.
2
What type of tactics does the 'Batavia' spyware campaign use?
The campaign employs phishing emails that use contract-related lures to deceive victims.
3
Which geographic region is primarily impacted by the 'Batavia' spyware?
The spyware primarily targets organizations within Russia.
4
What security risks are associated with this spyware campaign?
The risks include potential data breaches and surveillance of sensitive industrial information.
5
What specific software or programming languages are referenced in connection with this spyware?
The affected software includes tools related to Kaspersky, Visual Basic, and Delphi.