Emerging Hacktivist Malware Threats in Eastern Europe: A 2026 Analysis
Hacktivist groups in Eastern Europe are increasingly deploying sophisticated malware, including polymorphic ransomware and fileless malware, targeting critical infrastructure and leveraging advanced C2 infrastructures.
Executive Takeaway — TL;DR
- Category:
- Offensive Tools
- Severity:
- Medium
- Actor Type:
- Hacktivist
- Geography:
- Eastern Europe
- Confidence:
- Confirmed
- Source:
- Raptor Cyber Intelligence
- Read Time:
- 5 min
In early 2026, Eastern Europe has witnessed a significant escalation in cyber activities attributed to hacktivist groups. These entities are employing advanced malware techniques, such as polymorphic ransomware, rootkits, and fileless malware, to disrupt critical infrastructure and influence geopolitical narratives.
Emerging Malware Families and Reverse Engineering Findings
Recent analyses have identified several novel malware families utilized by hacktivist groups:
-
RomCom: This malware family has been linked to the Void Rabisu Group, also known as RomCom, Tropical Scorpius, or Storm-0978. RomCom conducts both financial cybercrime and intelligence collection via cyberespionage. (ics-cert.kaspersky.com)
-
VoidLink: A sophisticated malware strain observed in late 2025, VoidLink employs advanced obfuscation techniques to evade detection by traditional security measures. Its polymorphic nature allows it to adapt and change its code structure, making reverse engineering efforts challenging.
Reverse engineering of these malware families has revealed a trend towards modular architectures, enabling attackers to update or modify components without redeploying the entire payload. This modularity enhances the malware's adaptability and persistence within targeted networks.
Polymorphic Ransomware and Rootkits
Hacktivist groups have increasingly adopted polymorphic ransomware to maximize the impact of their attacks. These ransomware variants can alter their code upon each execution, complicating detection and analysis efforts. For instance, a pro-Ukraine hacktivist group breached Russian military accounts, deploying polymorphic ransomware to disrupt operations and exfiltrate sensitive data. (cert.europa.eu)
Rootkits have also been identified in several incidents, providing attackers with deep system access and the ability to maintain control over compromised systems. These rootkits often operate at the kernel level, making them particularly difficult to detect and remove.
Fileless Malware
The use of fileless malware has been on the rise among hacktivist groups. By residing in memory and avoiding traditional file systems, fileless malware can execute malicious activities without leaving traces on disk, thereby evading many conventional security tools. This approach is particularly effective in environments with robust endpoint detection and response systems.
Command and Control (C2) Infrastructure Analysis
Hacktivist groups are increasingly leveraging sophisticated C2 infrastructures to coordinate attacks and exfiltrate data. These infrastructures often involve the use of encrypted communication channels and decentralized networks to enhance resilience against takedown efforts. For example, the Qilin ransomware group utilized a complex C2 network to orchestrate attacks against Romanian oil pipeline operator Conpet, demonstrating a high level of operational sophistication. (cert.europa.eu)
Conclusion
The cyber threat landscape in Eastern Europe is evolving, with hacktivist groups adopting more sophisticated malware techniques and operational strategies. Organizations in the region must enhance their cybersecurity measures, focusing on advanced threat detection, rapid incident response, and comprehensive network monitoring to mitigate the risks posed by these emerging threats.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
Related Intelligence

Escalating Pegasus Deployments: New Zero-Click Campaigns Target Civil Society in Serbia

Global Surge in Mercenary Spyware: Apple Issues Urgent Alerts to Targets Across 110 Countries

