Numerous cyberattacks on Russia and the Commonwealth of Independent States (CIS) nations have been connected to the threat actor Rare Werewolf (previously Rare Wolf).
The attackers’ preference for utilizing trustworthy third-party software versus creating their own malicious binaries is a defining characteristic of this threat, according to Kaspersky. “PowerShell scripts and command files are used to carry out the malicious functionality of the campaign detailed in this article.
The assaults aim to remotely access compromised servers, spoof login credentials, and install the bitcoin miner XMRig. A lower number of infections were also reported in Belarus and Kazakhstan, but the activity affected hundreds of Russian users from engineering colleges and industrial businesses.
An advanced persistent threat (APT) group with a history of targeting organizations in Russia and Ukraine is referred to as Rare Werewolf read more about Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
