logo

Squid Werewolf Mimic as Recruiters Attacking Job Seekers To Exfiltrate Personal Data

ID: 78d25ea1-cf95-5890-90a7-9ad27eb44442

STIX ID: report--78d25ea1-cf95-5890-90a7-9ad27eb44442

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2025-03-18

Date Updated: 2026-04-21

Author: Tushar Subhra Dutta

...
...

A phishing campaign attributed to Squid Werewolf (APT37/Reaper Group) impersonates recruiters to deliver password-protected ZIPs containing LNK files masquerading as PDFs; the LNK executes a PowerShell command that extracts Base64 payloads, deploys a malicious DLL and configuration, persists by copying dfsvc.exe to the startup folder, and contacts hwsrv-1253398.hostwindsdns.com to retrieve AES-128-CBC encrypted payloads. The malware includes sandbox and connectivity checks to avoid detection and is designed to exfiltrate sensitive information from targeted job seekers and employees; recommended mitigations include email security, endpoint detection and response, and monitoring for suspicious PowerShell and startup activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.