logo

Paper Werewolf APT Disguises EchoGather RAT As Adobe Reader Installer

ID: dca4692c-1cff-5452-9d65-fe858f781a5d

STIX ID: report--dca4692c-1cff-5452-9d65-fe858f781a5d

Feed Name: Cyber Press

Threat Score
85/100

Date Published: 2026-05-18

Date Updated: 2026-05-22

Author: Varshini

...
...

Paper Werewolf, an advanced persistent threat actor, conducted a sophisticated phishing campaign (March–April 2026) targeting Russian industrial, financial, and transport sectors. Attackers use weaponized PDFs that prompt an “Install Update” action to drop a ZIP containing a fake Acrobat plugin which installs the EchoGather RAT alongside a decoy PDF; EchoGather collects system details and awaits remote commands. The group also deploys a custom stealer called PaperGrabber that hunts for sensitive files, browser passwords, Telegram data, SSH keys and certificates, exfiltrating data to a private Telegram bot. Analysts observed varied downloaders (JavaScript, C++, .NET), use of registry persistence techniques, sandbox-evasion math checks, and several provided SHA-256 malicious archive hashes as indicators of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.