logo

Fluffy Wolf Phishing Attacks Push PowerLoader Malware

ID: 46a82041-e746-5acf-89f8-ea276960788d

STIX ID: report--46a82041-e746-5acf-89f8-ea276960788d

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-16

Date Updated: 2026-06-16

Author: Do Son

...
...

Fluffy Wolf conducted sophisticated phishing campaigns (Mar–May 2026) against Russian construction, consulting, manufacturing, engineering, retail and e‑commerce firms using malicious RARs, GitHub links and a newly observed PowerLoader MaaS downloader to deploy PureRAT (now with a Remote Desktop plugin), PureLogs stealer and Pay2Key ransomware; attackers use fileless PowerShell retrieval, inject payloads into trusted Windows processes, and employ anti‑forensic techniques to support theft and extortion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.