Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations

109.106.178.14

TLP:CLEAR
Active

IPv4 Address

Description

A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus...

Sightings (0)

No sightings recorded yet

Details

Name / Label
From Invoice to AnyDesk: Uncovering a Phishing Campaign Targeting Russian Aerospace Organizations
Pattern Type
STIX
Confidence
75%
Valid From
Jul 12, 2026 03:07
Total Sightings
0
Added
Jul 12, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of 109.106.178.14

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.