Hackers pose as women seeking romance to spy on Russian soldiers
A previously unknown cyber espionage group, SiribClone, has been targeting Russian military personnel by impersonating women seeking romantic relationships. The group’s primary goal is to gather battlefield intelligence through malware deployment and phishing attacks, focusing on stealing sensitive data and monitoring communications. This tactic highlights a sophisticated espionage campaign aimed at exploiting trust and access within the Russian armed forces.
The SiribClone group, identified by Russian cybersecurity firm F6, began its operations in the summer of 2025 and has been actively targeting members of the Russian armed forces, particularly those stationed in border regions and combat zones. The campaign utilizes a multi-pronged approach, primarily leveraging Telegram to initiate conversations with servicemen and then tricking them into downloading malicious applications or providing credentials. This tactic allows the group to install spyware and gain access to victim’s devices and communications. The group has been distributing Android spyware named SafeLoveStealer, capable of stealing data and recording audio, alongside desktop malware dubbed SiribGrabber, designed to exfiltrate files from infected systems.
