In short: PT Expert Security Center (the threat intelligence arm of Positive Technologies) publicly disclosed a previously unknown APT group in early September 2026. Since May 2026, the group has run at least six targeted espionage campaigns against Russian state institutions — regional executive government bodies, Ministry of Defence structures, and the Federal Penitentiary Service (FSIN). The infection vector is a phishing email carrying an ISO optical disc image disguised as a pre-election PDF document.
Targets and attacker profile
On September 1, 2026, PT Expert Security Center published findings on a previously undocumented APT group. Over five months — May through September 2026 — the group ran at least six espionage campaigns directed exclusively at Russian state and security institutions. No attribution to any known APT has been established; researchers rate the group's technical capabilities as high, citing its exclusive reliance on fully custom tools and its use of election-timed lures.
Confirmed victims fall into two tiers. The September 2026 campaign targeted executive government bodies in several Russian regions — structures responsible for regional administration, budgetary oversight, and personnel data at the federal-subject level. Earlier campaigns hit Ministry of Defence structures and the Federal Penitentiary Service (FSIN). For broader context on the APT threat landscape, see the LiMP VPN blog.
How the attack works: ISO instead of PDF
The infection chain is deceptively simple but technically deliberate. A government employee receives a work email with a subject line tied to the upcoming State Duma elections on September 18, 2026. The attachment is an ISO optical disc image (.iso file).
The ISO format is not a coincidence. Many corporate email gateways and antivirus solutions scan document types (PDF, DOCX, XLSX) but are not always configured to inspect optical disc images. Inside the ISO are three executable files (.exe), each given a PDF document icon via icon substitution. To the recipient, the archive looks like a folder of election-related documents. Double-clicking what appears to be a PDF triggers malicious code instead.
Infection proceeds in two stages. First, a reconnaissance module runs, collecting device configuration, running processes, and network infrastructure data. Then a custom backdoor is installed — fully bespoke code with no traces of any known public or commercial framework. The backdoor connects to a command-and-control (C2) server, giving operators covert remote access to the compromised workstation. The objective is espionage: extracting documents, correspondence, and intelligence about personnel and infrastructure.
Why this matters beyond the public sector
At first glance this looks like a story about government and security services. But the attack vector — phishing → ISO → backdoor — is not confined to state-targeted APT operations. The same technique is increasingly adapted for corporate espionage and attacks on government contractors.
Any organisation that handles public-sector contracts or supplies government bodies can become the next link in an attack chain. Supply-chain compromise — reaching the real target through a trusted vendor — has long been a standard APT technique. We covered a parallel threat — corporate data exposure through unsanctioned services — in our piece on shadow AI and data leaks.
The broader picture: per Positive Technologies, the state sector was Russia's second most targeted sector in Q1 2026. Campaigns with an espionage motive represent a growing share of incidents.
Practical protection: what to do
Treat ISO attachments as a red flag. ISO optical disc images are never a legitimate format for a business document. If an email arrives with a .iso attachment — even with a PDF icon — do not open it. Report it to your information security team immediately.
Show file extensions. Enable file extensions in your file manager (Windows: View → check "File name extensions"). A file with a PDF icon but an .exe extension is a clear indicator of deception.
Do not open unexpected attachments, even when the subject seems timely. Attackers deliberately choose high-relevance themes — elections, tax deadlines, regulatory updates — as lures to lower suspicion.
Layer your technical defences: an updated antivirus with behavioural analysis, a corporate email gateway with sandboxed attachment inspection, and an EDR solution on endpoints. ISO attachments should be automatically blocked or executed only in an isolated environment.
Encrypt traffic at the network layer. Once installed, a backdoor reaches its C2 server over the internet. If device traffic runs through an encrypted VPN tunnel, a network-level observer — ISP or SOC — sees only an encrypted outbound stream, not its content or destination. LiMP VPN builds that on-device tunnel with a strict no-logs policy: no connection log is stored for your provider or third parties. A VPN will not stop a backdoor already on the device, but it is part of a defence-in-depth posture that complicates network-level traffic analysis. See plans on our pricing page.
