'Librarian Ghouls' Cyberattackers Strike at Night
ID: 31d7876a-d7d4-5ae0-8488-208c0f8e19c5
STIX ID: report--31d7876a-d7d4-5ae0-8488-208c0f8e19c5
Feed Name: Dark Reading
Librarian Ghouls is running an active, stealthy campaign targeting primarily Russian industrial and academic organizations using password-protected phishing archives that install scripts and legitimate utilities (AnyDesk, Blat, Defender Control, 4t Tray Minimizer, etc.) to exfiltrate data, disable defenses, schedule nightly wake windows for remote access, and deploy an XMRig cryptominer; the campaign leverages living-off-the-land tactics to evade detection and has compromised hundreds of victims since December.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
