logo

Tracing a Paper Werewolf campaign through AI-generated decoys and Excel XLLs

ID: 9be3b66b-3084-511c-8a6b-c913cfaaa83b

STIX ID: report--9be3b66b-3084-511c-8a6b-c913cfaaa83b

Feed Name: Intezer Blog

Threat Score
70/100

Date Published: 2025-12-19

Date Updated: 2026-04-28

Author: Nicole Fishbein

...
...

This report analyzes a targeted cyber-espionage campaign attributed to Paper Werewolf (GOFFEE) that delivers a 64-bit backdoor called EchoGather via malicious Excel XLL add-ins and WinRAR path-traversal archives exploiting CVE-2025-8088; it describes the loader's DLL_THREAD_DETACH evasion, the backdoor's reconnaissance, beaconing and file transfer capabilities, C2 infrastructure, decoy documents, and provides hashes and other IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.