Paper Werewolf hackers are reportedly targeting Russian entities with a new implant called PowerModul.

According to a new report from Kaspersky , the malicious activity took place between July and December 2024 and primarily targeted organizations in the media, telecommunications, construction, and energy sectors, while government agencies were also targeted .
The Paper Werewolf hackers, also known as GOFFEE, have carried out at least seven campaigns since 2022, according to BI.ZONE, with the attacks mainly targeting government, energy and financial organizations and SMEs.
How do Paper Werewolf team attacks work?
According to researchers, the group's attacks are aimed at distributing malware for espionage purposes, but they also change passwords belonging to employee accounts.
See also: Hackers distribute ViperSoftX malware via cracked software
The attacks themselves are launched via phishing emails, which contain a decoy document with macros. If the victim opens the document and enables the macros, it paves the way for the deployment of a remote access trojan called PowerRAT.
The malware is designed to deliver a next-stage payload, often a customized version of the Mythic framework agent, known as PowerTaskel and QwakMyAgent. Another tool also used is a malicious IIS module, called Owowa, which helps recover Microsoft Outlook credentials entered by users in the web client.
In the most recent attacks, observed by Kaspersky, Paper Werewolf hackers start with a malicious RAR archive attachment containing an executable file. This is disguised as a PDF or Word using a double extension (e.g. *.pdf.exe or *.doc.exe). When the executable file is launched, the decoy file is downloaded from a remote server and displayed to the user. At the same time, the infection proceeds to the next stage (in the background).
The file itself is a Windows system file (explorer.exe or xpsrchvw.exe), with part of its code containing malicious shellcode. The shellcode is similar to that of previous attacks, but additionally contains an obfuscated Mythic agent, which immediately begins communicating with the command and control (C2) server.
See also: Authorities arrested customers of Smokeloader malware
The alternative attack sequence is much more sophisticated, using a RAR file that embeds a Microsoft Office document with a macro. This acts as a dropper to deploy and launch PowerModul, a PowerShell script that receives and executes additional PowerShell scripts from the C2 server.
The backdoor is said to have been in use since early 2024, with threat actors initially using it to download and execute PowerTaskel on compromised hosts. Some of the other payloads installed via PowerModul include: FlashFileGrabber, FlashFileGrabberOffline, USB Worm.
PowerTaskel is functionally similar to PowerModul in that it also executes PowerShell scripts sent from the C2 server. But in addition, it can send information about the targeted environment in the form of a “checkin” message, as well as execute other commands received from the C2 server as tasks. It is also equipped to escalate privileges using the PsExec utility.

Malware protection
The first and most important way to protect yourself from malware is to install reliable security software. This software should include protection against viruses, spyware, malware, and other attacks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additionally, it is important to keep your operating system and all your applications up to date. These updates often include security that can protect your computer from the latest known trojans.
See also: Fake Microsoft Office add-ins push malware via SourceForge
You should also be careful with the emails and messages you receive. A lot of malware is spread through phishing attacks, so avoid opening attachments or clicking on links from unknown sources.
Using strong passwords and changing them regularly can also help protect against attacks. Also, using two-factor authentication can add an extra layer of security.
Finally, information security training can be particularly useful. Understanding the ways in which malware invades system and how to protect against it can help you stay safe.
Source: thehackernews.com
