Also known as: tracked as, Aug 7
A sophisticated spear-phishing campaign targeting Russian aerospace and aviation organizations has been identified, likely attributed to the Rare Werewolf threat group. The attack begins with fraudulent emails impersonating a legitimate Russian aerospace research institute, delivering password-protected archives containing malicious installers. The campaign employs living-off-the-land techniques, abusing legitimate tools including AnyDesk, Blat, WinRAR, and Tray Minimizer to establish persistent remote access. The attack chain deploys portable AnyDesk with unattended access configured using a predefined password, exfiltrates configuration data via SMTP to attacker-controlled infrastructure, and establishes persistence through scheduled tasks. The operators conceal their activities by minimizing the AnyDesk interface and removing forensic artifacts. This methodology aligns with previously documented Rare Werewolf campaigns targeting strategically important sectors across Russia, Belarus, and Kazakhstan, par...
Targeted Sectors
Targeted Countries / Regions
No AI analysis yet.
No techniques linked yet.
No tools linked yet.
No campaigns linked yet.
No observed data linked yet.
No references recorded yet.
0
Techniques
0
Tools
0
Campaigns
6
IOCs
0
Observed Data
0
Tactics