logo

Take 2: Scaly Wolf persistently targets Russian engineering company’s secrets

ID: e05e753c-3ed5-55f7-a0f2-8517a90e4036

STIX ID: report--e05e753c-3ed5-55f7-a0f2-8517a90e4036

Feed Name: Dr.Web News

Threat Score
75/100

Date Published: 2025-08-19

Date Updated: 2026-04-27

...
...

Doctor Web investigated a targeted May–June 2025 intrusion against a Russian engineering firm carried out by the Scaly Wolf APT: initial phishing with passworded ZIPs delivered Trojan.Updatar.1 (a downloader using RockYou-based obfuscation), which fetched Updatar modules and Meterpreter payloads; attackers performed credential theft (HandleKatz), lateral movement via RDP, deployed tunneling tools (Chisel, frp), and used BITS jobs and registry changes for persistence. The report details malware samples, C2 infrastructure (notably roscosmosmeet.online and 77.105.161.30), post-exploitation tooling, IoCs, and mapped MITRE ATT&CK techniques, and recommends tightening AV configuration and patching.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.