Operation HumanitarianBait Uses Fake Aid Documents to Deploy Python Spyware

https://hackread.com/wp-content/uploads/2026/05/operation-humanitarianbait-fake-aid-docs-python-spyware-1024x576.png

A new Python spyware campaign dubbed Operation HumanitarianBait is currently targeting Russian speakers by weaponizing the very documents meant to help them. This discovery, made by Cyble Research and Intelligence Labs (CRIL), shows that cybercriminals are making clever use of trusted web services to hide a powerful surveillance tool and using the guise of Russian humanitarian aid efforts to infect systems with it.

Infection Chain and Delivery Methods

According to researchers, the campaign is currently active as of May 2026. The attack starts with sending phishing emails containing a RAR archive, inside which is a malicious LNK file (SHA-256: 8a100cbdf79231e70cee2364ebd9a4433fda6b4de4929d705f26f7b68d6aeb79).

This isn’t a simple shortcut because it contains hidden code that PowerShell extracts and runs in memory. With this anti-sandbox technique, the hackers ensure the malware stays inert when being tested by automated security scanners.

“This is a deliberate anti-sandbox technique, as the malware will not execute if the original...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://media.wired.com/photos/6a0e32d330c7f349f26634db/191:100/w_1280,c_limit/Grok-Has-Over-100-Million-Monthly-Users-Business-2255064635.jpg

Filing: SpaceX set aside $530M for potential litigation losses, including lawsuits involving Grok's “Spicy” mode, which it described as a “heightened risk”

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. App Spotlight: Quo for Zoho CRM — App Spotlight brings you hand-picked solutions that enhance your