logo

Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan

ID: b663ca10-285a-5d78-9e43-80f8436fc828

STIX ID: report--b663ca10-285a-5d78-9e43-80f8436fc828

Feed Name: The Hacker News

Threat Score
82/100

Date Published: 2024-06-04

Date Updated: 2026-05-05

Author: [email protected] (The Hacker News)

...
...

Positive Technologies and other researchers attribute Operation Lahat to the HellHounds APT, which has used a custom Decoy Dog backdoor (derived from the open-source Pupy RAT) to infiltrate at least 48 Russian organizations across sectors including IT, government, space, and telecom. The report confirms a Windows Decoy Dog variant deployed via a loader that fetches decryption keys, documents DNS tunneling C2, use of a modified 3snake tool for credential theft, and notes initial access vectors such as compromised SSH credentials and third-party contractors, enabling long-term covert persistence.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.