Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign — Threadlinqs Intelligence
As of 2026-07-18, Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign is a high-severity malware threat attributed to Forbidden Hyena, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 41 indicators of compromise.
Threat ID: TL-2026-1496 · Severity: HIGH · Status: ACTIVE · Category: MALWARE
Attribution: Forbidden Hyena · HACKTIVISM
The hacktivist-turned-extortion cluster Forbidden Hyena ran a multi-stage campaign (December 2025-January 2026) distributing RAR archives with obfuscated VBS/batch loaders and decoy PDFs to deploy a
BI.ZONE Threat Intelligence documented the evolution of Forbidden Hyena, a cluster it classifies within its 'Hyena' taxonomy tier for hacktivist (non-nation-state) actors, distinct from state-sponsored 'Werewolves'. Previously known for ideologically motivated website defacements, the group has pivoted toward high-stakes corporate intrusion, credential theft, and dual-use ransomware/wiper deployment between December 2025 and January 2026.
The intrusion chain begins with RAR archive delivery (via phishing or drive-by download) containing a batch script (1.bat) that launches an obfuscated VBScript loader (1.vbs) through cscript.exe/wscript.exe. The loader displays a decoy PDF to the victim while silently downloading the BlackReaperRAT payload from attacker infrastructure (confluence.dada-tuda[.]ru, big-tree[.]ru). BlackReaperRAT is a previously undocumented VBS-based RAT that establishes persistence via Registry Run keys (HKLM/HKCU), Windows Task Scheduler entries, and Startup-folder LNK files. Uniquely, it retrieves commands not from a conventional C2 channel but by parsing the HTML og:description meta tag of a private Telegram channel (t.me/+QFbPfHfSq3E0N2M6), supporting getid, cmd, dwl, update, and httpshell command primitives. The RAT stores a per-victim bot ID at %APPDATA%\BlackReaper.id and includes unused, dormant code for recursive filesystem searches across txt/log/csv/xml/script files, suggesting a broader data-collection capability not yet activated in observed samples.
A notable feature of this campaign is confirmed and suspected use of generative AI/LLM tooling in malware development: researchers assess the reverse-shell binary (4458.exe) was 'presumably generated using an LLM', and multiple VBScript and PowerShell deployment scripts show hallmark signs of AI-authored code (verbose, non-obfuscated structure, inconsistent-but-functional style) that let the operators rapidly iterate custom payloads per target with minimal manual engineering effort.
Following initial access, the actor pursues lateral movement using SSH key deployment (ssh.ps1), reverse shells over port 4458, and AnyDesk remote-access software for persistent hands-on-keyboard access. Credential theft is achieved via Volume Shadow Copy Service (VSS) abuse to extract NTDS.dit, SAM, and SYSTEM registry hives (using scripts such as ntds.ps1), and via SharpView for Active Directory reconnaissance. The group also runs garble-obfuscated Sliver C2 framework implants from a second infrastructure cluster (2.59.163[.]169) in parallel with BlackReaperRAT, indicating a mixed toolkit spanning custom and commodity C2.
For impact, Windows victims receive the Milkyway ransomware (a rebrand of the group's existing Blackout Locker with only minor code modification), which appends the .milkyway extension, terminates 46+ processes (including SQL Server, Oracle, Firefox, Veeam, OneDrive) and 22+ services (including Windows Defender, VSS, and backup utilities) before encryption, and displays a Cyrillic-titled ransom note ('СИСТЕМНОЕ УВЕДОМЛЕНИЕ' — 'SYSTEM NOTIFICATION') via a binary masquerading as WindowsSystemHelper.exe. Persistence for the locker itself is maintained through additional registry entries, a WindowsSystemMaintenance scheduled task, and LNK files.
Linux hosts in target environments instead receive viper_linux, a wiper that performs AES-256-GCM encryption/destruction of files across the filesystem (excluding /proc, /sys, /dev, /tmp, /boot and similar system paths), persists via /lib/systemd/systemd-svchelper and an hourly /etc/cron.d/systemd-cron cron entry, and self-deletes after killing its own process to hinder forensic recovery.
The combination of a novel RAT, Telegram-based covert C2, AI-assisted tool development, commodity Sliver implants, and cross-platform ransomware/wiper impact reflects a maturing hacktivist actor operating with tradecraft approaching that of financially motivated ransomware crews, while retaining destructive/disruptive intent c
Target sectors: corporate enterprise generic, government administration
Target regions: Unknown / not specified in source reporting
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 41 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
MALWARE, HIGH, threat intelligence, cybersecurity, T1566, T1566.001, T1059.005, T1059.001, T1059.003, T1204.002, T1547.001, T1053.005, T1053.003, T1543.002