logo

Sleep with one eye open: how Librarian Ghouls steal data by night

ID: 9d79f316-fd5d-5776-a5cb-0b8cdff39cb4

STIX ID: report--9d79f316-fd5d-5776-a5cb-0b8cdff39cb4

Feed Name: Securelist by Kaspersky

Threat Score
75/100

Date Published: 2025-06-09

Date Updated: 2026-04-29

Author: Kaspersky

...
...

This report documents an active APT campaign named Librarian Ghouls (aka Rare Werewolf / Rezet) targeting Russian and CIS entities through phishing with password‑protected archives; attackers install legitimate utilities (AnyDesk, Blat, customized RAR) and use command files and PowerShell to disable defenses, exfiltrate credentials and registry hives, and deploy an XMRig crypto miner. The analysis includes deployment flow (installer -> rezet.cmd -> bat.bat -> wol.ps1), detailed TTPs, lists of malicious and legitimate binaries used, infrastructure (domains and an IP), victim profile (hundreds of Russian users, industrial and educational targets), and numerous IOCs (hashes, domains, filenames) for detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.