• News/
  • https://www.bleepingcomputer.com/news/security/batavia-windows-spyware-campaign-targets-dozens-of-russian-orgs/

'Batavia' Windows spyware campaign targets dozens of Russian orgs

BleepingComputer
·
Bill Toulas
·
Published Jul 7, 2025
·
Updated

A previously undocumented spyware called ‘Batavia’ has been targeting large industrial enterprises in Russia in a phishing email campaign that uses contract-related lures. The researchers believe the operation has been active since at least last year in July and is ongoing. Based on telemetry data, the phishing emails delivering Batavia have reached employees at several dozen Russian organizations have been targeted. Since January 2025, the campaign has increased in intensity and peaked towards the end of February. Researchers at Kaspersky say that the attacks begin with an email embedding a link disguised as a contract attachment. Clicking it downloads an archive that with a malicious Visual Basic Encoded script (.VBE) file. When executed, the script profiles the host system and sends the details to the attacker’s command and control server (C2). Then it downloads the next stage payload, WebView.exe, from oblast-ru[.]com. The second stage is a Delphi-based malware that displays a fake contract to the victim for diversion while collecting system logs, documents, and capturing screenshots in the background. The collected data is then exfiltrated to ru-exchange[.]com, while the malware uses a hash of the first 40,000 bytes of each file to avoid redundant uploads. Finally, it fetches the third-stage payload, ‘javav.exe,’ a C++ data stealer, and adds a startup shortcut to execute it on OS boot. The final payload expands the data collection even more, targeting additional file ty...

Read full article

Affected Software

3 affected components
Kaspersky N/A
Visual Basic N/A
Delphi N/A
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main subject of the article?

The article discusses a spyware campaign named 'Batavia' that targets large industrial enterprises in Russia.

2

What type of tactics does the 'Batavia' spyware campaign use?

The campaign employs phishing emails that use contract-related lures to deceive victims.

3

Which geographic region is primarily impacted by the 'Batavia' spyware?

The spyware primarily targets organizations within Russia.

4

What security risks are associated with this spyware campaign?

The risks include potential data breaches and surveillance of sensitive industrial information.

5

What specific software or programming languages are referenced in connection with this spyware?

The affected software includes tools related to Kaspersky, Visual Basic, and Delphi.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203