'Fluffy Wolf' Spreads Meta Stealer in Corporate Phishing Campaign
ID: 0fec391c-aeb1-5683-807d-b397d79f30bf
STIX ID: report--0fec391c-aeb1-5683-807d-b397d79f30bf
Feed Name: Dark Reading
Date Published: 2024-03-20
Date Updated: 2026-05-05
Author: Elizabeth Montalbano, Contributing Writer
Bi.Zone researchers report an active phishing campaign by an actor called Fluffy Wolf that impersonates a construction company to send password-protected accounting report attachments; when opened these lures deploy Remote Utilities to fetch Meta Stealer and other payloads (WarZone RAT, XMRig, and legitimate tools). The actor, active since 2022, has carried out at least ~140 attacks primarily against Russian organizations, leveraging low-skill access to malware-as-a-service and legitimate remote-access tools to exfiltrate credentials, cookies, FTP data, VPN and crypto wallet information; the report includes IoCs and MITRE ATT&CK mappings and recommends managed email security and threat intelligence monitoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
