logo

Attackers Exfiltrate AnyDesk Configuration Data via Blat SMTP in Aerospace Phishing Campaign

ID: c8fc85ec-4179-584b-86a9-ff31f68f1f43

STIX ID: report--c8fc85ec-4179-584b-86a9-ff31f68f1f43

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-07-07

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

**Executive summary:** A targeted spear-phishing campaign impersonating an aerospace research institute sends password-protected RAR attachments that deploy a multi-stage dropper which installs a portable AnyDesk, configures unattended access and persistence (scheduled task “Auto apdate”), and exfiltrates AnyDesk configuration and credential artifacts via Blat SMTP; the report includes IOCs (hashes, IPs, domains), links the activity to the Rare Werewolf cluster, and recommends blocking abused tooling, inspecting password-protected attachments, monitoring AnyDesk artifacts and outbound SMTP, and applying application allowlisting and stronger email authentication.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.