- Joined
- Jan 20, 2026
- Messages
- 345
- Reaction score
- 2,254
The F6 discovered the cyber-espy group SiribClone, which attacks Russian servicemen.

The new cyber-spy group SiribClone is aimed at Russian servicemen and is trying to access their Telegram accounts, as well as data from computers and Android smartphones. According to F6, attackers get acquainted with potential victims in messengers, are presented by girls or volunteers and offer to download the application for photo sharing, open an archive with a document or pass authorization on a fake Telegram page.
The group was discovered by F6 Threat Intelligence. Experts came on the trail of SiribClone in February 2026 and later found that the earliest activity dates back to at least the summer of 2025. The purpose of the attacks were servicemen of the Armed Forces of the Russian Federation in the border areas and in the SVO zone.

SiribCloné operates in two directions. The group distributes malware for computers and smartphones to collect personal, technical, geographic and other data. Separately, the attackers try to gain access to Telegram accounts to read correspondence and study contacts.
To infect computers, SiribClone uses the SiribGrabber malware. The main task of the program is data theft. In the winter of 2026, the attackers sent out a ZIP archive with an allegedly departmental document on the introduction of an information interaction system. Inside was a file, the opening of which started downloading malware.
In May 2026, the group changed the bait and began to use the fake website of the Immortal Regiment movement. When you click on the "Participate" button, the user downloaded the archive under the guise of the questionnaire. Opening a file from the archive led to the download of the malware.
For attacks on smartphones, SiriClone actively uses social engineering. Attackers get acquainted with the military through dating apps, messengers and other platforms. In the correspondence, the interlocutor can introduce himself as a programmer and suggest to test the application, or offer a safe exchange of photos through a separate program.
Under the guise of Safeintim, SafeintimZ and ZafeintimZ applications, the previously unknown SECLoveStealer spyware is distributed. The program requests a minimum of permits and simulates ordinary work, but in parallel transmits audio, video, photos, documents, geolocation, network data and Wi-Fi modem to attackers. The malware also allows you to burn sound from the microphone and send audio in which speech is heard.
Another scenario is built around the image of volunteers. Attackers communicate with servicemen on behalf of people who allegedly collect requests for humanitarian assistance, and then offer to fill out a table on the link.
Correspondence with such interlocutors can end not only with the installation of spyware, but also by compromising the Telegram account. F6 found in the infrastructure of SiribClone phishing pages for theft of Telegram-sessions. The pages were disguised as Telegram’s cloud storage, adding to the community, obtaining medical analyses and authorization in a fake application.
On the fake pages, the user was asked to enter the phone number, the code to log in to Telegram and, if necessary, the password of two-factor protection. After entering the data, the attackers gained access to the account and could read the correspondence in real time.
The F6 also found an application that attacked viewed the messages of compromised accounts. The interface displays lists of the captured accounts, channels, chat rooms and notes by users. The notes indicated a brief description of the person, position and other information.
Description of geolocations, mention of the ranks and military units helped F6 to conclude that SiribClone is engaged in military espionage. The group is not limited to the mass collection of accounts, but tries to obtain information about specific servicemen and related contacts.

The new cyber-spy group SiribClone is aimed at Russian servicemen and is trying to access their Telegram accounts, as well as data from computers and Android smartphones. According to F6, attackers get acquainted with potential victims in messengers, are presented by girls or volunteers and offer to download the application for photo sharing, open an archive with a document or pass authorization on a fake Telegram page.
The group was discovered by F6 Threat Intelligence. Experts came on the trail of SiribClone in February 2026 and later found that the earliest activity dates back to at least the summer of 2025. The purpose of the attacks were servicemen of the Armed Forces of the Russian Federation in the border areas and in the SVO zone.

SiribCloné operates in two directions. The group distributes malware for computers and smartphones to collect personal, technical, geographic and other data. Separately, the attackers try to gain access to Telegram accounts to read correspondence and study contacts.
To infect computers, SiribClone uses the SiribGrabber malware. The main task of the program is data theft. In the winter of 2026, the attackers sent out a ZIP archive with an allegedly departmental document on the introduction of an information interaction system. Inside was a file, the opening of which started downloading malware.
In May 2026, the group changed the bait and began to use the fake website of the Immortal Regiment movement. When you click on the "Participate" button, the user downloaded the archive under the guise of the questionnaire. Opening a file from the archive led to the download of the malware.
For attacks on smartphones, SiriClone actively uses social engineering. Attackers get acquainted with the military through dating apps, messengers and other platforms. In the correspondence, the interlocutor can introduce himself as a programmer and suggest to test the application, or offer a safe exchange of photos through a separate program.
Under the guise of Safeintim, SafeintimZ and ZafeintimZ applications, the previously unknown SECLoveStealer spyware is distributed. The program requests a minimum of permits and simulates ordinary work, but in parallel transmits audio, video, photos, documents, geolocation, network data and Wi-Fi modem to attackers. The malware also allows you to burn sound from the microphone and send audio in which speech is heard.
Another scenario is built around the image of volunteers. Attackers communicate with servicemen on behalf of people who allegedly collect requests for humanitarian assistance, and then offer to fill out a table on the link.
Correspondence with such interlocutors can end not only with the installation of spyware, but also by compromising the Telegram account. F6 found in the infrastructure of SiribClone phishing pages for theft of Telegram-sessions. The pages were disguised as Telegram’s cloud storage, adding to the community, obtaining medical analyses and authorization in a fake application.
On the fake pages, the user was asked to enter the phone number, the code to log in to Telegram and, if necessary, the password of two-factor protection. After entering the data, the attackers gained access to the account and could read the correspondence in real time.
The F6 also found an application that attacked viewed the messages of compromised accounts. The interface displays lists of the captured accounts, channels, chat rooms and notes by users. The notes indicated a brief description of the person, position and other information.
Description of geolocations, mention of the ranks and military units helped F6 to conclude that SiribClone is engaged in military espionage. The group is not limited to the mass collection of accounts, but tries to obtain information about specific servicemen and related contacts.