Sticky Werewolf Expands Cyber Attack Targets in Russia and Belarus
ID: 22ba4140-aa83-5479-9da7-3944f6b0283a
STIX ID: report--22ba4140-aa83-5479-9da7-3944f6b0283a
Feed Name: The Hacker News
Researchers disclosed that the 'Sticky Werewolf' threat actor has conducted phishing campaigns against organizations in Russia and Belarus (pharmaceutical, microbiology/vaccine research, aviation), using RAR archives with LNK files that launch binaries from WebDAV servers; the chain includes NSIS-packed executables, AutoIt scripts and crypter variants to bypass defenses and deploy RATs and info-stealers (e.g., Rhadamanthys, Ozone). The report also references related clusters (Sapphire Werewolf, Fluffy Wolf, Mysterious Werewolf) employing additional malware and backdoors such as Amethyst/SapphireStealer and RingSpy, while attribution remains uncertain.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
