Paper Werewolf APT Disguises EchoGather RAT As Adobe Reader Installer
ID: dca4692c-1cff-5452-9d65-fe858f781a5d
STIX ID: report--dca4692c-1cff-5452-9d65-fe858f781a5d
Feed Name: Cyber Press
Paper Werewolf, an advanced persistent threat actor, conducted a sophisticated phishing campaign (March–April 2026) targeting Russian industrial, financial, and transport sectors. Attackers use weaponized PDFs that prompt an “Install Update” action to drop a ZIP containing a fake Acrobat plugin which installs the EchoGather RAT alongside a decoy PDF; EchoGather collects system details and awaits remote commands. The group also deploys a custom stealer called PaperGrabber that hunts for sensitive files, browser passwords, Telegram data, SSH keys and certificates, exfiltrating data to a private Telegram bot. Analysts observed varied downloaders (JavaScript, C++, .NET), use of registry persistence techniques, sandbox-evasion math checks, and several provided SHA-256 malicious archive hashes as indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
