Russian Power Companies, IT Firms, and Govt Agencies Hit by Decoy Dog Trojan
ID: b663ca10-285a-5d78-9e43-80f8436fc828
STIX ID: report--b663ca10-285a-5d78-9e43-80f8436fc828
Feed Name: The Hacker News
Positive Technologies and other researchers attribute Operation Lahat to the HellHounds APT, which has used a custom Decoy Dog backdoor (derived from the open-source Pupy RAT) to infiltrate at least 48 Russian organizations across sectors including IT, government, space, and telecom. The report confirms a Windows Decoy Dog variant deployed via a loader that fetches decryption keys, documents DNS tunneling C2, use of a modified 3snake tool for credential theft, and notes initial access vectors such as compromised SSH credentials and third-party contractors, enabling long-term covert persistence.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
