logo

Cyber spies use fake New Year concert invites to target Russian military

ID: 98998457-52a9-5213-be28-964291d8ac0c

STIX ID: report--98998457-52a9-5213-be28-964291d8ac0c

Feed Name: The Record from Recorded Future News

Threat Score
70/100

Date Published: 2025-12-22

Date Updated: 2026-05-01

...
...

Goffee (Paper Werewolf) has run a targeted campaign against Russian military and defense-industry organizations using malicious Excel XLL files that drop a new backdoor called EchoGather; the malware collects system information, executes commands, and exfiltrates data to a C2 server disguised as a food-delivery website. Phishing lures in Russian (including AI-generated documents and forged official letters) were used to entice victims, and researchers note prior Goffee activity involving USB-stealer malware and exploitation of a WinRAR zero-day, though the group's tradecraft still shows linguistic and technical gaps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.