Fluffy Wolf Phishing Attacks Push PowerLoader Malware
ID: 46a82041-e746-5acf-89f8-ea276960788d
STIX ID: report--46a82041-e746-5acf-89f8-ea276960788d
Feed Name: securityonline.info
Fluffy Wolf conducted sophisticated phishing campaigns (Mar–May 2026) against Russian construction, consulting, manufacturing, engineering, retail and e‑commerce firms using malicious RARs, GitHub links and a newly observed PowerLoader MaaS downloader to deploy PureRAT (now with a Remote Desktop plugin), PureLogs stealer and Pay2Key ransomware; attackers use fileless PowerShell retrieval, inject payloads into trusted Windows processes, and employ anti‑forensic techniques to support theft and extortion.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
