Researchers warn about ‘Goffee’ spilling onto Russian flash drives
ID: 1d09676d-4a13-52ce-9e2f-34f5dbfdb1b8
STIX ID: report--1d09676d-4a13-52ce-9e2f-34f5dbfdb1b8
Feed Name: The Record from Recorded Future News
Threat Score
Kaspersky and BI.ZONE report that an APT tracked as Goffee (aka Paper Werewolf) has deployed a custom backdoor, PowerModul, and associated modules (FlashFileGrabber, USB Worm) to exfiltrate files from USB flash drives and spread via removable media; the group has targeted Russian media, telecoms, government, construction, and energy organizations since at least 2022, delivering malware via phishing emails with malicious archives and impersonated institutions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
