<ul data-eligibleForWebStory="true">Increase in detections of files like договор-2025-5.vbe, приложение.vbe, and dogovor.vbe.Targeted attack through bait emails with malicious links to infect Russian organizations.Batavia spyware steals internal documents in a three-stage infection process.Malware components include VBS script, executables like WebView.exe and javav.exe.Kaspersky detects files as HEUR:Trojan.VBS.Batavia.gen and HEUR:Trojan-Spy.Win32.Batavia.gen.