logo

Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer

ID: 2cd9721b-375d-5ab2-9c96-d2ece1cfc6b7

STIX ID: report--2cd9721b-375d-5ab2-9c96-d2ece1cfc6b7

Feed Name: GBHackers

Threat Score
88/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Mayura Kathir

...
...

Paper Werewolf (GOFFEE) ran a targeted March–April 2026 campaign against Russian industrial, financial, and transport organizations using phishing PDFs that prompt a fake Adobe Reader update; the bundled Inno Setup installer deploys EchoGather RAT and a VB.NET stealer (PaperGrabber), plus multiple shellcode downloaders and Mythic-based post-exploitation implants. The report lists active C2 domains/URLs, describes advanced evasion (anti-VM checks, djb2-derived parameter, RSA-4096/AES encrypted comms), and provides IoCs for detection and threat-hunting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.