A previously unknown spyware called Batavia has come under the microscope of cybersecurity experts, as it is being used in targeted phishing campaigns targeting large industrial companies in Russia .
Batavia activity has been detected since at least July 2024 and, according to Kaspersky, has escalated significantly since January 2025. The attacks are carried out via deceptive emails containing fake contract, leading victims into a multi-stage infection scheme.
See also: Android spyware Catwatchful leaks 62,000 user logins
How the Batavia spyware
The attack begins with a phishing email, which contains a link pretending to be an attached contract. With a simple click, the victim downloads a malicious .VBE file, which activates the first stage of the spyware.

The script creates a profile of the victim's system and sends the information to a C2 server ( Command & Control). It then downloads the WebView . exe file from oblast – ru [.] com and displays a fake contract to keep the user busy, while simultaneously collecting:
- System files
- Documents
- Screenshots
The data is secretly sent to another domain (ru-exchange[.]com), with the software using hashing to avoid repeated uploads and reduce the likelihood of detection.
See also: Android spyware targets Russian military
The third stage of the attack involves the javav.exe, a malicious program written in C++, which is automatically launched every time the computer is started. This phase expands the data collection, now including:
- Pictures
- Presentations
- Emails
- Spreadsheets
- TXT and RTF files
Kaspersky says there are indications of a fourth stage , possibly with the file windowsmsg.exe , but it has not yet been identified for further analysis.
Espionage or industrial surveillance?
Although researchers do not attribute a clear motive for the campaign, the goals and nature of the campaign suggest industrial or state espionage. The fact that multiple Russian industrial organizations and that the Batavia spyware focuses on collecting critical documents and financial data reinforces this possibility.
See also: Paragon's Graphite spyware targeted journalists
The Batavia campaign is part of a broader context of targeted, high-precision, where the human factor remains the Achilles' heel of corporate security systems. Attackers exploit not only technological gaps, but also the trust and naivety of employees in the face of "innocent" contracts or documents.

Spyware protection
One of the most effective ways to protect yourself is to use reputable security. These programs scan your device for spyware and remove it. They also offer real-time protection, alerting you when an app tries to install spyware on your device.
It's also important to keep your operating system and all programs up to date. These updates often include security fixes that can help protect your computer from spyware.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Another important tip is to be careful with the emails and messages you receive. This software is often spread through phishing, where attackers try to convince you to click on a malicious link or open a dangerous attachment.
Finally, it's important to always have backups of your important files. While this won't protect you directly, it will help you recover your data if your device is compromised.
Source: www.bleepingcomputer.com
