Forbidden Hyena Adopts AI-Generated BlackReaperRAT and Milkyway (Blackout Locker) Ransomware in Telegram-C2 Campaign

Forbidden Hyena Adopts AI-Generated BlackReaperRAT and (TL-2026-1496), also tracked as Blackout Locker (pre-rebrand name for Milkyway ransomware), is a high-severity malware campaign, first published 2026-07-18. It is attributed to Forbidden Hyena with medium confidence, affects Microsoft Windows (all supported desktop/server versions), maps to 37 MITRE ATT&CK techniques (T1003.002, T1003.003, T1005), and is covered by 9 detection rules and 41 indicators of compromise.

Key facts for TL-2026-1496

Threat ID
TL-2026-1496
Also known as
Blackout Locker (pre-rebrand name for Milkyway ransomware)
Severity
HIGH
Status
ACTIVE
Category
MALWARE
First published
2026-07-18
Last reviewed
2026-07-18
Attribution
Forbidden Hyena
Attribution confidence
MEDIUM
Motivation
HACKTIVISM
Target sectors
corporate enterprise generic, government administration
Target regions
Unknown / not specified in source reporting
Detection rules
9
Indicators of compromise
41

Malware and tooling in Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

Malware and tooling: BlackReaperRAT, Milkyway (Blackout Locker), viper_linux, AnyDesk, Plink, SharpView, Sliver - S0633

The hacktivist-turned-extortion cluster Forbidden Hyena ran a multi-stage campaign (December 2025-January 2026) distributing RAR archives with obfuscated VBS/batch loaders and decoy PDFs to deploy a previously undocumented RAT, BlackReaperRAT, alongside a rebranded ransomware/locker (Blackout Locker, now 'Milkyway'). BI.ZONE observed AI/LLM-generated PowerShell and reverse-shell code across the tool chain, Telegram-channel-based C2 (commands hidden in HTML meta tags), and parallel use of garble-obfuscated Sliver C2 framework implants and a Linux AES-256-GCM wiper (viper_linux).

How Forbidden Hyena Adopts AI-Generated BlackReaperRAT and works

BI.ZONE Threat Intelligence documented the evolution of Forbidden Hyena, a cluster it classifies within its 'Hyena' taxonomy tier for hacktivist (non-nation-state) actors, distinct from state-sponsored 'Werewolves'. Previously known for ideologically motivated website defacements, the group has pivoted toward high-stakes corporate intrusion, credential theft, and dual-use ransomware/wiper deployment between December 2025 and January 2026.

The intrusion chain begins with RAR archive delivery (via phishing or drive-by download) containing a batch script (1.bat) that launches an obfuscated VBScript loader (1.vbs) through cscript.exe/wscript.exe. The loader displays a decoy PDF to the victim while silently downloading the BlackReaperRAT payload from attacker infrastructure (confluence.dada-tuda[.]ru, big-tree[.]ru). BlackReaperRAT is a previously undocumented VBS-based RAT that establishes persistence via Registry Run keys (HKLM/HKCU), Windows Task Scheduler entries, and Startup-folder LNK files. Uniquely, it retrieves commands not from a conventional C2 channel but by parsing the HTML og:description meta tag of a private Telegram channel (t.me/+QFbPfHfSq3E0N2M6), supporting getid, cmd, dwl, update, and httpshell command primitives. The RAT stores a per-victim bot ID at %APPDATA%\BlackReaper.id and includes unused, dormant code for recursive filesystem searches across txt/log/csv/xml/script files, suggesting a broader data-collection capability not yet activated in observed samples.

A notable feature of this campaign is confirmed and suspected use of generative AI/LLM tooling in malware development: researchers assess the reverse-shell binary (4458.exe) was 'presumably generated using an LLM', and multiple VBScript and PowerShell deployment scripts show hallmark signs of AI-authored code (verbose, non-obfuscated structure, inconsistent-but-functional style) that let the operators rapidly iterate custom payloads per target with minimal manual engineering effort.

Following initial access, the actor pursues lateral movement using SSH key deployment (ssh.ps1), reverse shells over port 4458, and AnyDesk remote-access software for persistent hands-on-keyboard access. Credential theft is achieved via Volume Shadow Copy Service (VSS) abuse to extract NTDS.dit, SAM, and SYSTEM registry hives (using scripts such as ntds.ps1), and via SharpView for Active Directory reconnaissance. The group also runs garble-obfuscated Sliver C2 framework implants from a second infrastructure cluster (2.59.163[.]169) in parallel with BlackReaperRAT, indicating a mixed toolkit spanning custom and commodity C2.

For impact, Windows victims receive the Milkyway ransomware (a rebrand of the group's existing Blackout Locker with only minor code modification), which appends the .milkyway extension, terminates 46+ processes (including SQL Server, Oracle, Firefox, Veeam, OneDrive) and 22+ services (including Windows Defender, VSS, and backup utilities) before encryption, and displays a Cyrillic-titled ransom note ('СИСТЕМНОЕ УВЕДОМЛЕНИЕ' — 'SYSTEM NOTIFICATION') via a binary masquerading as WindowsSystemHelper.exe. Persistence for the locker itself is maintained through additional registry entries, a WindowsSystemMaintenance scheduled task, and LNK files.

Linux hosts in target environments instead receive viper_linux, a wiper that performs AES-256-GCM encryption/destruction of files across the filesystem (excluding /proc, /sys, /dev, /tmp, /boot and similar system paths), persists via /lib/systemd/systemd-svchelper and an hourly /etc/cron.d/systemd-cron cron entry, and self-deletes after killing its own process to hinder forensic recovery.

The combination of a novel RAT, Telegram-based covert C2, AI-assisted tool development, commodity Sliver implants, and cross-platform ransomware/wiper impact reflects a maturing hacktivist actor operating with tradecraft approaching that of financially motivated ransomware crews, while retaining destructive/disruptive intent consistent with its hacktivist origins.

MITRE ATT&CK techniques used in TL-2026-1496

Credential Access

T1003.002 Security Account Manager; T1003.003 NTDS; T1552 Unsecured Credentials

Collection

T1005 Data from Local System; T1025 Data from Removable Media

Lateral Movement

T1021.004 SSH; T1570 Lateral Tool Transfer

Defense Evasion

T1027 Obfuscated Files or Information; T1036 Masquerading; T1070.004 File Deletion; T1140 Deobfuscate/Decode Files or Information

Persistence

T1053.003 Cron; T1053.005 Scheduled Task; T1543.002 Systemd Service; T1547.001 Registry Run Keys / Startup Folder

Execution

T1059.001 PowerShell; T1059.003 Windows Command Shell; T1059.005 Visual Basic; T1204.002 Malicious File

Discovery

T1069.002 Domain Groups; T1083 File and Directory Discovery; T1482 Domain Trust Discovery

Command and Control

T1071.001 Web Protocols; T1095 Non-Application Layer Protocol; T1102 Web Service; T1105 Ingress Tool Transfer; T1572 Protocol Tunneling

command-and-control

T1219 Remote Access Tools

Impact

T1485 Data Destruction; T1486 Data Encrypted for Impact; T1489 Service Stop; T1490 Inhibit System Recovery; T1561 Disk Wipe

Privilege Escalation

T1547.001 Registry Run Keys / Startup Folder

Initial Access

T1566 Phishing; T1566.001 Spearphishing Attachment

Exfiltration

T1567 Exfiltration Over Web Service

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

  • Microsoft — Windows (all supported desktop/server versions)
    Vulnerable versions: Windows 10; Windows 11; Windows Server
  • Linux — Linux servers (generic, systemd-based distributions)
    Vulnerable versions: systemd-based Linux distributions

Remediation for Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

Immediate actions

  • Block outbound access to identified C2 domains/IPs: confluence.dada-tuda[.]ru, dada-tuda[.]ru, big-tree[.]ru, 193.233.48.98, 2.59.163.169
  • Block or alert on the Telegram channel identifier +QFbPfHfSq3E0N2M6 in DNS/proxy logs where feasible
  • Hunt for %APPDATA%\BlackReaper.id and %LOCALAPPDATA%\lockp\run.lock artifacts across Windows endpoints
  • Alert on cscript.exe/wscript.exe spawning from RAR-extracted paths executing .vbs files
  • Quarantine and block RAR archives containing 1.bat/1.vbs file pairs at email/web gateways
  • Isolate hosts showing AnyDesk installation not sanctioned by IT alongside NTDS.dit access attempts

Workarounds

  • Disable Windows Script Host (WSH) organization-wide if not required for legitimate business scripts
  • Enforce application allow-listing to block unsigned AnyDesk/remote-access tool installers

Longer-term hardening

  • Deploy EDR with behavioral detection for VSS-based credential dumping (vssadmin, ntdsutil, esentutl against ntds.dit)
  • Restrict script host execution (cscript/wscript) via AppLocker/WDAC where not business-required
  • Implement network segmentation to limit SSH key-based lateral movement between Windows and Linux estate
  • Deploy Linux EDR/FIM to detect AES bulk-encryption behavior and unauthorized systemd unit creation
  • Monitor for garble-obfuscated Go binaries characteristic of Sliver C2 framework
  • Establish offline, immutable backups given dual ransomware/wiper impact capability

Timeline of Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

  • Forbidden Hyena campaign activity begins, deploying RAR-archive-delivered VBS loaders with BlackReaperRAT and Milkyway ransomware, per BI.ZONE telemetry window (December 2025-January 2026).
  • BlackReaperRAT payloads observed retrieving Telegram-channel-hosted commands via HTML og:description meta-tag parsing, establishing bot-ID-tracked persistence at %APPDATA%\BlackReaper.id.
  • Garble-obfuscated Sliver C2 framework implants identified operating from a second infrastructure cluster (2.59.163.169), used in parallel with BlackReaperRAT.
  • Observed use of ssh.ps1 and ntds.ps1 scripts, SharpView, AnyDesk, and Volume Shadow Copy abuse for NTDS.dit/SAM/SYSTEM extraction and Active Directory lateral movement.
  • Milkyway ransomware (rebranded Blackout Locker) deployed against Windows hosts, terminating 46+ processes and 22+ services before encrypting files with the .milkyway extension.
  • viper_linux wiper deployed against Linux hosts in parallel intrusions, performing AES-256-GCM destructive encryption and self-deletion post-execution.
  • BI.ZONE Threat Intelligence publishes 'Forbidden Hyena adopts BlackReaperRAT in AI-powered campaigns', disclosing the malware family, Telegram C2 mechanism, AI/LLM-generated code findings, and full IOC set.
  • Secondary security media (Security Online, Security.Land) republish and expand on BI.ZONE findings, characterizing the shift from hacktivist defacement to AI-assisted corporate extortion.

Sources cited for Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

Threats related to Forbidden Hyena Adopts AI-Generated BlackReaperRAT and

Detection coverage for TL-2026-1496

As of 2026-07-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1496 across Splunk SPL, Microsoft KQL and Sigma, covering 41 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats