HomeSecurityATP Rare Werewolf uses legitimate software in attacks

ATP Rare Werewolf uses legitimate software in attacks

The hacking group known as Rare Werewolf (formerly Rare Wolf) has been linked to a series of cyberattacks targeting Russia and the countries of the Commonwealth of Independent States (CIS).

See also: What are SSRF attacks and how to protect yourself

Rare Werewolf

The purpose of the attacks is to remotely access compromised systems, steal credentials, and install the XMRig. The activity affected hundreds of Russian users, including industrial enterprises and technical schools, while a smaller number of breaches were also recorded in Belarus and Kazakhstan.

Rare Werewolf, also known as Librarian Ghouls and Rezet, is the alias of an advanced persistent threat (APT) group that has a history of attacking organizations in Russia and Ukraine. It is believed to have been active since at least 2019.

According to BI.ZONE, the threat actor gains initial access via phishing emails, exploiting this push to intercept documents, data from the Telegram messenger, and install tools such as Mipko Employee Monitor, WebBrowserPassView , and Defender Control. These tools are used to interact with the infected system, collect passwords, and disable antivirus software.

The latest set of attacks recorded by Kaspersky reveals the use of phishing emails as a means of distributing malware, leveraging password-protected ZIP files containing executable files to initiate the infection.

See also: "PathWiper" attack targets critical infrastructure in Ukraine

Included within the file is an installer used to install a legitimate tool, 4t Tray Minimizer, as well as other payloads, including a deceptive PDF file that simulates a payment order.

t-mobile router hackers
ATP Rare Werewolf uses legitimate software in attacks

These intermediate payloads are then used to download additional files from a remote server , including Defender Control and Blat — a legitimate tool that allows stolen data to be sent to an email address controlled by the attacker via the SMTP protocol. The attacks are also characterized by the use of AnyDesk remote access software and a Windows batch script to facilitate data theft and installation of the cryptocurrency mining tool.

A notable feature of the batch script is that it launches a PowerShell script with automatic power-on capabilities on the victim's computer at 1 a.m. local time, giving attackers access to the system for a four-hour window via AnyDesk. The system is then powered off at 5 a.m. via a scheduled task.

The revelation comes as Positive Technologies revealed that a cybercrime group called DarkGaboon is targeting Russian entities using the LockBit 3.0.

See also: Is the Interlock ransomware group behind the attack on Kettering Health?

Based on the above, we observe an attack profile that is typical of advanced threat groups (APTs) such as Rare Werewolf, with a well-organized and multi-layered modus operandi. This type of attack highlights the need for multi-layered cybersecurity, especially in critical infrastructure and educational institutions that are traditionally considered more “vulnerable” targets.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS