Paper Werewolf APT Spreads EchoGather RAT via Fake Adobe Installer
ID: 2cd9721b-375d-5ab2-9c96-d2ece1cfc6b7
STIX ID: report--2cd9721b-375d-5ab2-9c96-d2ece1cfc6b7
Feed Name: GBHackers
Paper Werewolf (GOFFEE) ran a targeted March–April 2026 campaign against Russian industrial, financial, and transport organizations using phishing PDFs that prompt a fake Adobe Reader update; the bundled Inno Setup installer deploys EchoGather RAT and a VB.NET stealer (PaperGrabber), plus multiple shellcode downloaders and Mythic-based post-exploitation implants. The report lists active C2 domains/URLs, describes advanced evasion (anti-VM checks, djb2-derived parameter, RSA-4096/AES encrypted comms), and provides IoCs for detection and threat-hunting.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
