logo

Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus

ID: 22ba4140-aa83-5479-9da7-3944f6b0283a

STIX ID: report--22ba4140-aa83-5479-9da7-3944f6b0283a

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-06-10

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed that the 'Sticky Werewolf' threat actor has conducted phishing campaigns against organizations in Russia and Belarus (pharmaceutical, microbiology/vaccine research, aviation), using RAR archives with LNK files that launch binaries from WebDAV servers; the chain includes NSIS-packed executables, AutoIt scripts and crypter variants to bypass defenses and deploy RATs and info-stealers (e.g., Rhadamanthys, Ozone). The report also references related clusters (Sapphire Werewolf, Fluffy Wolf, Mysterious Werewolf) employing additional malware and backdoors such as Amethyst/SapphireStealer and RingSpy, while attribution remains uncertain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.