Cyber spies use fake New Year concert invites to target Russian military
ID: 98998457-52a9-5213-be28-964291d8ac0c
STIX ID: report--98998457-52a9-5213-be28-964291d8ac0c
Feed Name: The Record from Recorded Future News
Goffee (Paper Werewolf) has run a targeted campaign against Russian military and defense-industry organizations using malicious Excel XLL files that drop a new backdoor called EchoGather; the malware collects system information, executes commands, and exfiltrates data to a C2 server disguised as a food-delivery website. Phishing lures in Russian (including AI-generated documents and forged official letters) were used to entice victims, and researchers note prior Goffee activity involving USB-stealer malware and exploitation of a WinRAR zero-day, though the group's tradecraft still shows linguistic and technical gaps.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
