logo

Researchers warn about ‘Goffee’ spilling onto Russian flash drives

ID: 1d09676d-4a13-52ce-9e2f-34f5dbfdb1b8

STIX ID: report--1d09676d-4a13-52ce-9e2f-34f5dbfdb1b8

Feed Name: The Record from Recorded Future News

Threat Score
72/100

Date Published: 2025-04-11

Date Updated: 2026-05-01

...
...

Kaspersky and BI.ZONE report that an APT tracked as Goffee (aka Paper Werewolf) has deployed a custom backdoor, PowerModul, and associated modules (FlashFileGrabber, USB Worm) to exfiltrate files from USB flash drives and spread via removable media; the group has targeted Russian media, telecoms, government, construction, and energy organizations since at least 2022, delivering malware via phishing emails with malicious archives and impersonated institutions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.