Paper Werewolf Threat Actor Targets Flash Drives With New Malware
ID: ce87b13b-cb01-5be6-a405-db51c94bd438
STIX ID: report--ce87b13b-cb01-5be6-a405-db51c94bd438
Feed Name: Dark Reading
Date Published: 2025-04-11
Date Updated: 2026-05-05
Author: Kristina Beek, Associate Editor, Dark Reading
Paper Werewolf (aka Goffee) has been observed deploying a new PowerShell downloader implant named PowerModul that fetches additional components including FlashFileGrabber (steals documents from USB/removable drives) and USB Worm (spreads via flash drives). Kaspersky and BI.ZONE reported multiple campaigns from July–December 2024 targeting Russian media, telecommunications, construction, government, energy and finance organizations; the actor's operations focus on cyber espionage and have also included destructive actions and credential manipulation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
