Skip to main content
Mallory
Back to intelligence
credential-stealer-activityphishing-campaign-intelligencegovernment-diplomatic-threatstate-sponsored-espionage

SiribClone Used Romance Lures and Telegram Phishing to Spy on Russian Soldiers

Updated 2d agoFirst seen Jun 5, 20262 sources

Russian cybersecurity firm F6 says a previously undocumented espionage group it calls SiribClone has targeted Russian military personnel since at least summer 2025, using fake romantic interest and humanitarian-assistance pretexts on Telegram, messaging apps, and dating sites to collect battlefield-relevant intelligence. The operation sought personal data, correspondence, contacts, geolocation, device information, and access to victims’ Telegram accounts, with activity concentrated on servicemen in border regions and combat zones.

Researchers identified two malware families tied to the campaign: SafeLoveStealer for Android, spread through deceptive links and APK files such as Safeintim.apk, and SiribGrabber for Windows, delivered through .LNK files disguised as military-themed documents and later through an "Immortal Regiment" themed website serving malicious archives. F6 also found phishing infrastructure designed to steal Telegram sessionString tokens and an internal operator platform called Kontur used to store hijacked Telegram sessions, review intercepted messages, and track victim details; the company did not attribute the activity to a known threat actor or country.

Share:
SiribClone Used Romance Lures and Telegram Phishing to Spy on Russian Soldiers
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Jun 9, 20263d ago

SiribClone begins targeting Russian military personnel

F6 reported that the previously undocumented espionage group SiribClone has targeted Russian military personnel since at least summer 2025 using social-engineering lures on Telegram and other platforms.

Hackers pose as women seeking romance to spy on Russian soldiers | The Record from Recorded Future News
Jun 5, 20267d ago

F6 discloses SiribClone espionage campaign and malware families

F6 publicly reported on the SiribClone operation, describing romance and humanitarian-assistance lures targeting Russian soldiers, the SafeLoveStealer Android spyware, the SiribGrabber desktop malware, Telegram credential theft infrastructure, and the internal 'Kontur' platform used to manage stolen Telegram sessions.

F6: группировка SiribClone атакует российских военных через Telegram и шпионское ПО - Хакер

SiribClone launches Immortal Regiment-themed lure campaign

In May 2026, F6 observed a new SiribClone campaign using an 'Immortal Regiment' themed website to entice victims to download archives that deployed an updated SiribGrabber malware variant.

F6: группировка SiribClone атакует российских военных через Telegram и шпионское ПО - Хакер

Researchers observe SiribClone attacks in January-February 2026

F6 observed attacks during January and February 2026 in which SiribClone used messengers and dating sites to phish Russian military personnel and deliver Android spyware and Windows malware.

F6: группировка SiribClone атакует российских военных через Telegram и шпионское ПО - Хакер

SiribClone starts testing its tools

According to F6, SiribClone began testing its malware tooling in December 2025 ahead of later observed attacks against Russian servicemen.

F6: группировка SiribClone атакует российских военных через Telegram и шпионское ПО - Хакер
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

12 LINKEDOpen in app
Threat actors
1 linked
Organizations
3 linked
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.