'Sticky Werewolf' APT Stalks Aviation Sector
ID: a923311a-b6c5-5881-ad80-e0d9a0fbdbb1
STIX ID: report--a923311a-b6c5-5881-ad80-e0d9a0fbdbb1
Feed Name: Dark Reading
Threat Score
Sticky Werewolf, an APT active since at least April 2023, is running multi-stage phishing campaigns targeting aviation, defense-related organizations, and other strategic targets in the Russia–Ukraine context; attackers use archived attachments with LNK files to establish persistence, drop AutoIT scripts and batch files that evade security products, and ultimately deploy commercial remote access trojans and stealers for espionage and data exfiltration.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
