Organizations in Belarus, Kazakhstan, and Russia have emerged as targets of a phishing campaign conducted by a previously undisclosed hacking group called ComicForm since at least April 2025.
See also: MalTerminal AI malware: Abuse of OpenAI's GPT-4

The activity mainly targeted the sectors of industry, finance, tourism, biotechnology, research and commerce, according to cybersecurity firm F6.
The attack chain involves sending emails with subjects such as “Waiting for signed document”, “Invoice for Payment”, or “Agreement Act for Signature”, urging recipients to open an RR file, which contains a Windows executable file pretending to be a PDF document (e.g., “Акт_сверки pdf 010.exe”). The messages, written in Russian or English, are sent from email addresses registered in the .ru, .by and .kz.
The executable is a disguised .NET loader designed to launch a malicious DLL (“MechMatrix Pro.dll”), which then executes a third payload stage, another DLL named “Montero.dll” that acts as a dropper for the Formbook malware, while also creating a scheduled task and configuring exceptions in Microsoft Defender to evade detection.
Interestingly, the binary file contains Tumblr links that lead to harmless GIFs of comic book superheroes like Batman, giving the threat actor its name. “These images were not used in any attack, but were simply part of the malware code,” said F6 researcher Vladislav Kugan.
See also: CISA: Two malware exploits Ivanti EPMM vulnerabilities

Analysis of ComicForm's infrastructure revealed indications that phishing emails have also been directed against an unspecified company operating in Kazakhstan in June 2025 and a Belarusian bank in April 2025.
F6 also detected and blocked phishing emails sent to Russian industrial companies from the email address of an industrial company based in Kazakhstan as recently as July 25, 2025. These emails urge potential targets to click on an embedded link to verify their account and avoid potential banning.
Users who click on the link are redirected to a fake landing page that mimics the login page of a domestic document management service to facilitate credential theft, transmitting the entered information to a domain controlled by the attacker in the form of an HTTP POST.
The ComicForm attack, targeting the Belarusian bank, involved sending a phishing email with an invoice-themed bait to trick users into entering their email addresses and phone numbers into a form, which are then recorded and sent to an external domain.
The revelation comes as the NSHC ThreatRecon revealed details of a pro-Russian cybercriminal group that has targeted the industrial, energy, and semiconductor sectors in South Korea. The activity has been attributed to a group called SectorJ149 (also known as UAC-0050).
See also: CountLoader: Russian hackers use new malware loader

The attacks, observed in November 2024, began with spear-phishing emails targeting executives and employees using baits related to manufacturing facility purchases or requests for quotes, leading to the execution of malware families such as Lumma Stealer, Formbook , and Remcos RAT via a Visual Basic Script distributed as a Microsoft cabinet (CAB) file.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
