Vortex Werewolf Targets Organizations With Tor-Enabled RDP, SMB, SFTP, and SSH Backdoors
ID: a396f752-49f7-5a8d-b003-d52f5fe183c5
STIX ID: report--a396f752-49f7-5a8d-b003-d52f5fe183c5
Feed Name: GBHackers
Vortex Werewolf (SkyCloak) is an APT campaign targeting Russian government and defense organizations that uses Telegram-themed phishing to steal session credentials and deliver LNK/PowerShell droppers; the payload installs a Tor-hidden OpenSSH backdoor, obfs4 proxy, and scheduled tasks to maintain covert, persistent remote access. The report provides a technical deep dive into the infection chain, infrastructure (GitHub Pages, Cloudflare), TTPs, and seven file-hash indicators of compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
